Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC tunnel issue

Hello Sophos Community,

 

I have one IPsec tunnel established with one of our client, the tunnel is up, ACL is up(have configured multiple hosts that can be access on client side). The issues is that when we initiate connection from our side internal VM ip to one host from client network the connection is working 30 min, 1hour (no specific interval of time) and then the connection suddenly stops. I capture tcp dump on our sophos sg450 (UTM 9 )firewall and in that tcpdump i see only "in" packets but no "out packets" (attached printscreen). i tried to do a SNAT from our side, the same issue(only with one host from customer side i have this issue). So sometimes the connection is working again by itself and sometimes i need to manually reset the tunnel.

Also need to mention behind this firewall, i have another firewall configured and also on that i can see only in packets but no out packets(the policy on this firewall is allowed with any port and on sophos the firewall is set on Auto for traffic through IPsec tunnel).

 

Do you have any sugestion for this issue?Also i can mention that on that USG i have over 40 tunnels up and this is the only tunnel with this kind of issue.

 



This thread was automatically locked due to age.
Parents
  • Hallo Andrei and welcome to the UT Community!

    Is this a question about Sophos UTM?  If so, please show pictures of the Edits of the IPsec Policy on each side of the Tunnel.

    Cheers - Bob

    PS Moving this thread to the VPN forum.

  • Hello,

    I can only share the configuration from my side, because the other side is on the customer network i do not have access there.

    Phase 1 and Phase 2

    Gateway to customer network. I cannot share the IP's 

    Our Internal IP is NAT to one public ip. Also tried without Nat and same issue.

    Thank you!

Reply
  • Hello,

    I can only share the configuration from my side, because the other side is on the customer network i do not have access there.

    Phase 1 and Phase 2

    Gateway to customer network. I cannot share the IP's 

    Our Internal IP is NAT to one public ip. Also tried without Nat and same issue.

    Thank you!

Children