Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Outbound L2TP/IPSEC VPN fails

 Just installed a Sophos UTM 9 Home edition firewall.  Everything appears to be working well, but when I attempt to connect to a client VPN from my laptop on the internal network, I get a 789 error and it never connects.  

So my laptop on internal network - to UTM - to L2TP/IPSEC 

I have tried to review logs, but haven't found anything that explains why it isn't working.  I created a new firewall rule to allow all VPN protocols from my laptop to the endpoint VPN address.  Prior to doing that I saw dropped UDP traffic, but since that change, I don't see anything.  I also enabled logging on that firewall rule, but don't  know where to find those logs

Is there a simple box to check to allow outbound VPN traffic somewhere?  I also saw an earlier post that mentions a packet trace log, but I don't see anything like that from the UTM management web interface.  

 



This thread was automatically locked due to age.
Parents
  • Hi, Karl, and welcome to the UTM Community!

    The "packet trace" capability is with tcpdump at the command line, but I think you just need #1 in Rulz.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • #1 didn't help me, but rule 3.1 did.  I remembered when I setup my UTM initially, I didn't have 2 NICs in the configuration and had to add it later.  I had looked at Masquerading earlier, but there wasn't anything there and 'assumed' that the system would auto create one if it needed it.  Anyway, I create a rule for the internal network and now my VPNs connect quickly.

     

    Thanks!

Reply
  • #1 didn't help me, but rule 3.1 did.  I remembered when I setup my UTM initially, I didn't have 2 NICs in the configuration and had to add it later.  I had looked at Masquerading earlier, but there wasn't anything there and 'assumed' that the system would auto create one if it needed it.  Anyway, I create a rule for the internal network and now my VPNs connect quickly.

     

    Thanks!

Children
No Data