Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to site being blocked by Intrusion Protection

So the other day I did my every couple of months bounce of my comcast modem.  As this is recommended by them and normally everything goes just fine.  However I was having some issues with my additional addresses but once I called Comcast they magically cleared up lol.  Weird thing was that only 2 of my IPs were having an issue activated the inactive ones and those worked fine so I don't know what its issue was. 

Anyways here's the issue that remains.

I can connect to my SSL VPN just fine with my PC, phone, tablet so I know that my VPN IP is listening (now)

However my 2 friends with UTM's as well I cannot for the life of me figure out why they can't connect.

This is what I'm seeing in the logs

Jan 15 10:06:09 192.168.1.129 2016:01:15-10:06:09 phoenix-1 ulogd[16964]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="78:cd:8e:dc:29:42" dstmac="00:0c:29:f8:5b:d6" srcip="70.122.XXX.XXX" dstip="50.246.XXX.XXX" proto="6" length="60" tos="0x00" prec="0x20" ttl="50" srcport="33832" dstport="443" tcpflags="SYN"

I turned off the IPS but it didn't make a difference.  For whatever reason its just dropping the packets on the site to site.  Thank you all in advance for your help and long live astaro.org :)



This thread was automatically locked due to age.
Parents
  • Hey Bob,

    1st off glad to see you over here :). Ok so I use port 443 on this IP for my VPN because it allows me to still call home at places that block outbound traffic by port. I'll tell them to disable their VPN then enable it and let you know what I see. So far in the VPN logs I don't see anything since all the stuff for my 50. IP is being blocked by this scanner.
Reply
  • Hey Bob,

    1st off glad to see you over here :). Ok so I use port 443 on this IP for my VPN because it allows me to still call home at places that block outbound traffic by port. I'll tell them to disable their VPN then enable it and let you know what I see. So far in the VPN logs I don't see anything since all the stuff for my 50. IP is being blocked by this scanner.
Children
No Data