Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue with VPN IPsec

I everyone,

 

 

I work today on UTM Sophos and i would like to create a vpn connection between 2 UTM, but i have one problem with that.

When i go to Site-tp-site VPN and choose IPsec, my connection doesn't work. I look the Open Live log and i watch that : 

 

2019:05:24-10:34:24 utminfotec pluto[17747]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
2019:05:24-10:34:24 utminfotec pluto[17747]: loading aa certificates from '/etc/ipsec.d/aacerts'
2019:05:24-10:34:24 utminfotec pluto[17747]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
2019:05:24-10:34:24 utminfotec pluto[17747]: loading attribute certificates from '/etc/ipsec.d/acerts'
 
2019:05:24-10:34:24 utminfotec pluto[17747]: Changing to directory '/etc/ipsec.d/crls'
 
2019:05:24-10:34:24 utminfotec ipsec_starter[17740]: no default route - cannot cope with %defaultroute!!!
2019:05:24-10:34:24 utminfotec pluto[17747]: "S_VPNInfotec-Maison2": deleting connection
2019:05:24-10:34:24 utminfotec pluto[17747]: "S_VPNInfotec-Maison2" #5: deleting state (STATE_MAIN_I1)
2019:05:24-10:34:24 utminfotec pluto[17747]: added connection description "S_VPNInfotec-Maison2"
2019:05:24-10:34:24 utminfotec pluto[17747]: "S_VPNInfotec-Maison2" #6: initiating Main Mode

 

I think the issue was here but i don't found solution about that and i search everywhere  !!!

 

I hope you can help me

 

Thomas 



This thread was automatically locked due to age.
Parents Reply Children
  • Hi bob,

     

    Here you can find a diagram of my network, my address name internal have this configuration : IPv4 address 192.168.10.90 

                                                                                                                                               IPv4 Default GW address 192.168.10.2

     

    I just name it internal but i can make the same with external (wan) 

     

     

     

    Thanks for all your answer

     

    Thomas

  • Thanks, Thomas, seeing that notebook paper brought back memories of when I lived in Berlin.

    Is either endpoint is behind a NAT, that could cause the problem in the second set of log lines above.  If not, we need a new extract from the IPsec log.  Do the following:

    1. Confirm that Debug is not enabled.
    2. Disable the IPsec Connection.
    3. Start the IPsec Live Log and wait for it to begin to populate.
    4. Enable the IPsec Connection.
    5. Show us about 60 lines from enabling through the error.  Or through the line containing "IPsec SA established."

    Cheers - Bob

  • Hi bob,

     

    Debug is not enable

     

     

    I hope you can find my issue, 

     

    I have NAT on myu side and i enable NAT-T like this :

     

    Thanks for all your answer 

     

    Thomas

  • Thomas, change the 'Interface' for each IPsec Connection to "External" - does it work now?  If not, show us the log again, but copy and paste the text here instead of showing a screen capture.

    Cheers - Bob

  • I bob,

     

    it's a good day :D , i have resolv all my issue this morning. I take a picture of my configuration if someone who check here have the same problem as me before. 

     

     

    this configuration works, i hope you don't will see an error.

     

    My 2 UTM is behind NAT it's why i enable NAT-Transversal. For me, i had to make port forwarding on my router.

     

    Thanks for all your response

     

    Thomas

  • Salut Thomas,

    Bon travail !

    In fact, since both UTMs are behind a NAT, what also made this work was "Respond only" on the one side and specifying the VPN ID on the "Initiate Connection" side.

    Cheers - Bob