Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec tunnel - trafic not going through

I have UTM with private addresses on both interfaces. There is a router in front of the UTM. I have setup IPSec vpn tunnel between UTM (my side A) and another device about 10 days ago. It has been working until two days ago when traffic stopped going throug tunnel. The tunnel on UTM is green (operational), but traffic can't pass through tunnel anymore. I tried tracert from my internal network, it reaches UTM internal interfaces and no information after that. The same with tracert from UTM. 
In order to test IPsec , I setup ipsec tunnel between my utm A and UTM B. It won't establish until I setup VPN ID optional (I inserted ip address (private) of external interface of my UTM A. After that the tunnel established properly, and every traffic can pass through tunnel. So the tunnel with UTM is working properly. 
I checked routes and see there is a route for second tunnel (which is operational and working) that goes through ipsec tunnel.
But I can't see any route related to first tunnel (I have problem with)....

Has anyone some idea about that?


This thread was automatically locked due to age.
Parents
  • I can't ping public address on the other side of the tunnel from my UTM when ipsec tunnel is up. When I turn off ipsec tunnel I can ping it

    That is normal with IPsec tunnels with the UTM.

    You need to ask them if they have DPD and NAT-T selected.  If that doesn't give you the answer, then try #1 in Rulz.  Any luck?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I can't ping public address on the other side of the tunnel from my UTM when ipsec tunnel is up. When I turn off ipsec tunnel I can ping it

    That is normal with IPsec tunnels with the UTM.

    You need to ask them if they have DPD and NAT-T selected.  If that doesn't give you the answer, then try #1 in Rulz.  Any luck?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data