Guest User!

You are not Sophos Staff.

[7.480][BUG][ACK] IPSec site2site VPN Problems

Hi, I upgraded to 7.480 2 nights ago, and today I decided to check on the VPNs...
Firstly, I noticed it said
"1 of 8 IPSec SAs established"

I disabled the connection (I have one connection for all 8 tunnels), and re-enabled it.
Now, I have 7 of 8 SAs established, but unfortunately the one I use most is down [:(]

PF log shows 1 drop each time I try to restart the VPN connection:

2009:08:13-11:44:21 fw ulogd[3252]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" seq="0" initf="eth0" outitf="unknown" dstmac="00:24:21:2e:63:f4" srcmac="00:00:00:00:00:00" srcip="remote.vpngw.ip.addr" dstip="my.ext.ip.addr" proto="17" length="284" tos="0x00" prec="0x00" ttl="253" srcport="500" dstport="500" 

2009:08:13-12:02:31 fw ulogd[3252]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" seq="0" initf="eth0" outitf="unknown" dstmac="00:24:21:2e:63:f4" srcmac="00:00:00:00:00:00" srcip="remote.vpngw.ip.addr" dstip="my.ext.ip.addr" proto="17" length="88" tos="0x00" prec="0x00" ttl="253" srcport="500" dstport="500" 
2009:08:13-12:05:51 fw ulogd[3252]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" seq="0" initf="eth0" outitf="unknown" dstmac="00:24:21:2e:63:f4" srcmac="00:00:00:00:00:00" srcip="remote.vpngw.ip.addr" dstip="my.ext.ip.addr" proto="17" length="204" tos="0x00" prec="0x00" ttl="253" srcport="500" dstport="500" 


today's ipsec.log is attached.

The connection I'm having trouble with is 
SA:  192.168.11.0/24=my.ext.ip.addr     remote.vpngw.ip.addr=10.42.6.0/24

Thanks,
Barry
ipsec.log.zip
Parents Reply
  • Have you taken a look at IPTABLES?  Maybe a rule isn't being added by the Astaro properly... is the remote IP in question a DNS host in your configuration?  If so, try a static host entry in your astaro config for that remote IP.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data