Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec Responding to Main Mode AFTER initiating Quick Mode

Hi all,

I am experiencing a very strange behavior with an IPsec tunnel between a customer's site (Checkpoint) and our UTM9:

It seems to me that every evening at the same time our customer kills all IPsec connections - somewhat ungracefully.

 

Then the next morning our IPsec tunnel is sometimes online sometimes offline, but anyhow I see the following log entries whenever I try to ping something through the tunnel:

2018:03:09-08:03:16 utm-1 pluto[7368]: "S_REF_IpsSitXXX_0" #227715: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP {using isakmp#224532}
2018:03:09-08:03:16 utm-1 pluto[7368]: packet from 212.183.15.178:500: ignoring Vendor ID payload [FRAGMENTATION]
2018:03:09-08:03:16 utm-1 pluto[7368]: packet from 212.183.15.178:500: ignoring Vendor ID payload [f4ed19e0c114eb516faaac0ee37daf2807b4381f000000010000138d5aa231b4...]
2018:03:09-08:03:16 utm-1 pluto[7368]: "S_REF_IpsSitXXX_0" #227716: responding to Main Mode
2018:03:09-08:03:16 utm-1 pluto[7368]: "S_REF_IpsSitXXX_0" #227716: Peer ID is ID_IPV4_ADDR: 'xxx.xxx.xxx.xxx'
2018:03:09-08:03:16 utm-1 pluto[7368]: "S_REF_IpsSitXXX_0" #227716: sent MR3, ISAKMP SA established
2018:03:09-08:03:16 utm-1 pluto[7368]: "S_REF_IpsSitXXX_0" #227716: received Delete SA payload: deleting ISAKMP State #224532

I understand that our utm tries to initiate a quick mode, as the main mode is not expired yet (at least from our point of view), but then it receives a Main Mode response from the customer's firewall?

After theese entries no further quick mode or retry connects are logged and whenever I repeat the ping I am observing the same behavior and log entries. My workaround is to disable the IPsec profile and reenabling it again to force a full initialization of the tunnel.

could someone explain that behavior?

 

Thanks in advance!



This thread was automatically locked due to age.
Parents
  • This is just a guess - do both sides have DPD enabled?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob, good guess but unfortunately the answer is no!

    I have generally disabled DPD on our UTM.

     

    I don't know what our customer's site's preferences are but still UTM does not even try to connect... let me explain that:

     

    Since Friday 6PM the connection is dead.

    On the IPsec status page it says: "Error: no connection"

     

    When I disable and reenable the connection the tunnel is up and running again.

Reply
  • Hi Bob, good guess but unfortunately the answer is no!

    I have generally disabled DPD on our UTM.

     

    I don't know what our customer's site's preferences are but still UTM does not even try to connect... let me explain that:

     

    Since Friday 6PM the connection is dead.

    On the IPsec status page it says: "Error: no connection"

     

    When I disable and reenable the connection the tunnel is up and running again.

Children
  • The DPD setting has to be the same on both sides.  None of my clients has DPD disabled.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA