Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

no routing after Update 9.409-9 Cisco VPN

We use the "Cisco VPN client" feature for connection iPhones to the company network.

All worked perfect. Since the update 9.409-9 no traffic is routed through the vpn.

The vpn connection is establishing and shows no errors, but every connection from the iPhones is timed out. I can't ping trough the vpn.

Is there a bug in the 9.409-9 update?



This thread was automatically locked due to age.
Parents
  • Hi,

    there are two different ways the SHA2 hashes are truncated for L2TP / IPSec RemoteAccess VPN by various manufacturers. One way is the official RFC defined way to handle SHA2 and the other one is the GOOGLE way. In the GOOGLE way a truncation after 96 bits is happening.

    If you have connections problems with a mobile device, Check the knowledge base article https://community.sophos.com/kb/en-us/125796 to get further information. Other customers have been able to solve their problem by adapting the policy ("SHA2 256" or "SHA 256 96bit" or by using the command line option.

    We are working on a solution to support both ways at the same.

    Greetings

    Holger

Reply
  • Hi,

    there are two different ways the SHA2 hashes are truncated for L2TP / IPSec RemoteAccess VPN by various manufacturers. One way is the official RFC defined way to handle SHA2 and the other one is the GOOGLE way. In the GOOGLE way a truncation after 96 bits is happening.

    If you have connections problems with a mobile device, Check the knowledge base article https://community.sophos.com/kb/en-us/125796 to get further information. Other customers have been able to solve their problem by adapting the policy ("SHA2 256" or "SHA 256 96bit" or by using the command line option.

    We are working on a solution to support both ways at the same.

    Greetings

    Holger

Children