Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unstable RED tunnel and lots of martian source entries in kernel.log

Hello,

I tried to set up an UTM-to-UTM RED Firewall Server tunnel (no legacy).
Sometimes I get packetloss for around 10-20 seconds. Sometimes the tunnel doesn't even come up.
And I noticed lots of martian source entries in kernel.log after enabling this RED tunnel:

2023:01:25-14:07:21 MYUTMNAME kernel: [6324855.992965] IPv4: martian source RED-SERVER-IP from MY-WAN-IP, on dev eth5
2023:01:25-14:07:21 MYUTMNAME kernel: [6324855.993049] ll header: 00000000: ff ff ff ff ff ff XX XX XX XX XX XX XX XX ...........D..

(Loglines anonymized)

But if I use RED Firewall Server Legacy instead of RED Firewall Server it works without any packetloss/problems.
Also an IPSec tunnel works without any problems for weeks.

(I have multiple WAN interfaces facing the router of my company ISP)

What could be the problem here?

Regards
UTMaddict



This thread was automatically locked due to age.
Parents
  • Hey  ,

    Thank you for reaching out to the community, May we know the current firmware version on the UTM 9 ?

    • Firewall RED Server: Connects to a UTM using 9.700 or later.
    • Firewall RED Client: Connects to a UTM using 9.700 or later.
    • Firewall RED Server Legacy: Connects to a UTM using versions earlier than 9.700.
    • Firewall RED Client Legacy: Connects to a UTM using versions earlier than 9.700.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hey  ,

    Thank you for reaching out to the community, May we know the current firmware version on the UTM 9 ?

    • Firewall RED Server: Connects to a UTM using 9.700 or later.
    • Firewall RED Client: Connects to a UTM using 9.700 or later.
    • Firewall RED Server Legacy: Connects to a UTM using versions earlier than 9.700.
    • Firewall RED Client Legacy: Connects to a UTM using versions earlier than 9.700.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Children