Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Reset IPSec-Connection

Hi guys,

is there a possibility to send a ping to a host, and if there is no respond, to deaktivate and aktivate the IPSec Connection?

Greetings Oezay



This thread was automatically locked due to age.
Parents
  • There's nothing in WebAdmin for that, Özay, but it could be done from the command line.  What problem are you having?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    thank you for your quick reply.

    I have some Site-to-Site IPSec-Connections which are not working properly,they look established on both sides but communications over them is not possible.

    Deactivating and activating the Tunnel on the remote side solves the problem sometime, but in some cases i just can solve the problem if i deactivate the tunnel on the UTM. It would be great if i can send a ping from the utm to a host on the remote side and if i dont get any reply deactivate and activate the tunnel. On the remoteside i am allready doing something like that in most cases this helps but not everytime, but resetting the tunnel on the UTM solves my problem everytime.

    Greetings Özay

  • I've seen a similar problem several times before that were fixed by setting the UTM's NIC and the ISP's equipment to the same fixed speed/duplex settings.  Does doing that on both ends resolve your problem?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • The UTM is a virtual one. Is it enough to make the changes on the ESX and on the UTM?

  • I've not seen this in that situation.  I would say to configure all three places to the same, fixed settings: UTM, Host NIC and the ISP's equipment.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • play around with rekeying times (ike and ipsec)

    Set one side 10 seconds less/more  than the other and check the results.

Reply Children
No Data