Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG230 to Draytek 2960 IPSec VPN

I have five Draytek 2960 running IPSec VPNs to a Sophos XG230.

The Drayteks initiate the connection using IKE2.

I get an email from the Drayteks every 53 minutes saying the link dropped. (It reconnects.) IKE Phase 1 timeout is 28800 seconds, Phase 2 is 3600 seconds on the Drayteks. On the XG, it's 5400 and 3600.

I changed IKE Phase 2 on the Draytek to 7200 seconds. It still drops after 53 minutes.

I disabled Dead Peer Detection on the XG (it's a VPN server, the Drayteks initiate the connection). The VPN dropped and wouldn't connect until I enabled it.

I disabled "Re-key connection" on the XG. The VPN dropped and wouldn't connect until I enabled it.

I changed IKE Phase 2 on the XG to 28800. The VPN dropped and wouldn't connect until I changed it back to 5400.

How do I stop the VPN dying every 53 minutes?



This thread was automatically locked due to age.