Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED Tunnel trouble? Using UTM 2 UTM RED tunnel I have connections issues i dont with SSL Tunnel.

I was using a RED tunnel for a UTM 2 UTM VPN but for some reason I wasnt seeing the same bandwidth accross the interfaces, ie what one int was sending wasnt what one int was receiving.  Also I was unable to access http pages on remote hosts.  But when I use a UTM 2 UTM SSL tunnel it seems to be a lot better, i cant see the traffic as i dont have interfaces with SSL VPN.  But I was able to access the http pages.

What would cause this?  Also on a VPN what MTU settings do i use each end as both my sites have different MTU settings.

Thanks

JK



This thread was automatically locked due to age.
Parents
  • Hi John. This sounds somewhat like it could be a Firewall-Rules related issue. Have you tried troubleshooting the traffic with the Firewall Log? Do you see it entering and exiting the Tunnel? Do you have any Proxy Functionality in your Scenario?

    Please send me Spam gueselkuebel@sg-utm.also-solutions.ch

  • yeah firewall is all OK no dropped traffic from either side.

    I have a rule for both sites LAN, the RED interfaces ip's and each sites external ip. So it doesnt seem to be the firewall. I also disabled tunnel compression but its still not showing the same RX & TX each end, for some reason packets are being lost. Could it be MTU? One site has 1460 the other has 1492, what do i use for the RED interfaces MTU at each end? Do I use the same as the WAN MTU or do I take the lowest value 1460 and use that at both sites?

    As I mentioned I had to switch to an SSL tunnel to resolve some of the issues i was having but i need to use IPSEC or RED so I can have separate interfaces for the VPN's. I did think that RED was a good feature but if it is RED that is the issue then its disappointing. Im going to try an IPSEC tunnel next and see if the RX & TX looks the same with that?

    Do I create a new interface then when setting up IPSEC select that INT as the local INT and then tick Bind to Local Interface to have separate INT's for the tunnel like you do with RED?

    Thanks

    JK

    CompKickers

Reply
  • yeah firewall is all OK no dropped traffic from either side.

    I have a rule for both sites LAN, the RED interfaces ip's and each sites external ip. So it doesnt seem to be the firewall. I also disabled tunnel compression but its still not showing the same RX & TX each end, for some reason packets are being lost. Could it be MTU? One site has 1460 the other has 1492, what do i use for the RED interfaces MTU at each end? Do I use the same as the WAN MTU or do I take the lowest value 1460 and use that at both sites?

    As I mentioned I had to switch to an SSL tunnel to resolve some of the issues i was having but i need to use IPSEC or RED so I can have separate interfaces for the VPN's. I did think that RED was a good feature but if it is RED that is the issue then its disappointing. Im going to try an IPSEC tunnel next and see if the RX & TX looks the same with that?

    Do I create a new interface then when setting up IPSEC select that INT as the local INT and then tick Bind to Local Interface to have separate INT's for the tunnel like you do with RED?

    Thanks

    JK

    CompKickers

Children
  • JK, you won't get an interface object with an IPsec tunnel in the UTM. It's not clear why you want an interface, so I don't know if there's a different way to accomplish what you want.

    If one side has a WAN connection with 1460, then I would use that on both sides with a RED tunnel.

    Could you explain "what one int was sending wasnt what one int was receiving" using different words - I don't see the picture.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA