Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

s2s watchguard ipsec issues

Hi All,

I have an issue setting up an ipsec tunnel to a particular vendor.

I have a number of other tunnels running to watchguards and they all seem to be running fine.

However this one seems to be causing a bit of a headache.

I can't get past this error on the UTM

2016:02:28-00:15:20 firewall pluto[28993]: ERROR: "S_CMTG_IPSEC" #12: sendto on eth1 to xxx.xxx.xxx.xxx:500 failed in main_outI1. Errno 1: Operation not permitted

from what I can tell from the error one of the systems think one of us is behind a NAT, but none of us are, and we are both running a number of tunnels without issues to other vendors (plus I have a couple running to other watchguards)

I have tried amending the config to my side to be receive only which poses there is some form of a policy missmatch.

Anyways has anyone else had any issues like this?



This thread was automatically locked due to age.
Parents
  • Both endpoints must agree on DPD and NAT–T.  If that's not it, since you already have eliminated the possibility that either side is behind a NAT, are you certain that you don't have conflicting subnets in your LANs?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Both endpoints must agree on DPD and NAT–T.  If that's not it, since you already have eliminated the possibility that either side is behind a NAT, are you certain that you don't have conflicting subnets in your LANs?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children