This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM VPN "malformed payload in packet"

Hi Guys,

 

I have a site to site IPSEC VPN between two Sophos UTM, both on version 9.700-5. This VPN has more than one year and has been running good, stable, fine, until last night when out of the sudden, it came down. I have not touched in any form, any of these two devices lately (not even logged on them).

Sophos A - this is the remote device. i now have only ssh access on it.

Sophos B - the local device on which i have full access.

When the problem appeared, it seems Sophos A does not respond to the user portal anymore. I can ssh into it on the wan interface but i cannot access its gui because it is bounded to the LAN interface, or so i remember.

Checking the VPN logs on Sophos B, i see:

2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #238: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #238: starting keying attempt 195 of an unlimited number
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: initiating Main Mode to replace #238
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: received Vendor ID payload [strongSwan]
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: ignoring Vendor ID payload [Cisco-Unity]
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: received Vendor ID payload [XAUTH]
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: received Vendor ID payload [Dead Peer Detection]
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: received Vendor ID payload [RFC 3947]
2020:02:13-08:41:39 robfw1 pluto[10114]: "S_VPN-BUC" #239: enabling possible NAT-traversal with method 3
2020:02:13-08:41:40 robfw1 pluto[10114]: "S_VPN-BUC" #239: NAT-Traversal: Result using RFC 3947: no NAT detected
2020:02:13-08:41:40 robfw1 pluto[10114]: "S_VPN-BUC" #239: next payload type of ISAKMP Hash Payload has an unknown value: 119
2020:02:13-08:41:40 robfw1 pluto[10114]: "S_VPN-BUC" #239: malformed payload in packet
2020:02:13-08:41:50 robfw1 pluto[10114]: "S_VPN-BUC" #239: discarding duplicate packet; already STATE_MAIN_I3
2020:02:13-08:41:50 robfw1 pluto[10114]: "S_VPN-BUC" #239: next payload type of ISAKMP Hash Payload has an unknown value: 149
2020:02:13-08:41:50 robfw1 pluto[10114]: "S_VPN-BUC" #239: malformed payload in packet
2020:02:13-08:42:10 robfw1 pluto[10114]: "S_VPN-BUC" #239: discarding duplicate packet; already STATE_MAIN_I3
2020:02:13-08:42:10 robfw1 pluto[10114]: "S_VPN-BUC" #239: next payload type of ISAKMP Hash Payload has an unknown value: 181
2020:02:13-08:42:10 robfw1 pluto[10114]: "S_VPN-BUC" #239: malformed payload in packet
 
What i did:
- i thought maybe somehow the password has a problem (following other similar threads), but i compared the password from the remote gateway on Sophos A (from cli) with the one from Sophos B and they match.
- i rebooted both devices - no fix
- i disabled DPD and NAT-T on Sophos B -no fix
- modified MTU from 1500 to 1380 on Sophos B - no fix
- reverted all the above to initial config - no fix
 
I believe the problem is on Sophos A, but i don't know how to tshoot it.
 
Guys, any ideea?
 
Thx,
Radu


This thread was automatically locked due to age.
Parents
  • Later on, i managed to connect to the Sophos A device via l2tp and thus i was able to access the Webadmin and saw there that my Home License expired, thus disabling most of the features. Renewed it and now all is good. 
    How could i had seen this problem from the cli? In which logs should've i checked this?

  • Salut Radu,

    It sounds like your problem-solving skills served you well!

    In similar situations, the fallback, kernel and system logs.

    Was there anything in notifier.log about this?  Did you have notifications set up?  You should have gotten an email about the expiration and that would have been your clue.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Salut Radu,

    It sounds like your problem-solving skills served you well!

    In similar situations, the fallback, kernel and system logs.

    Was there anything in notifier.log about this?  Did you have notifications set up?  You should have gotten an email about the expiration and that would have been your clue.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Salut Bob,

    Sorry for the late reply. The notifier log shows lines like these:

     


    2020:02:12-21:09:09 ng_fw notifier[7626]: processing notification request for WARN-006
    2020:02:12-21:09:09 ng_fw notifier[7626]: not sending WARN-006 - over limit (0)
    2020:02:12-21:09:09 ng_fw notifier[7626]: successfully processed request for notification
    2020:02:12-21:09:09 ng_fw notifier[7631]: processing notification request for WARN-006
    2020:02:12-21:09:09 ng_fw notifier[7631]: not sending WARN-006 - over limit (0)
    2020:02:12-21:09:09 ng_fw notifier[7631]: successfully processed request for notification
    2020:02:12-21:13:23 ng_fw notifier[8274]: processing notification request for CRIT-861
    2020:02:12-21:13:24 ng_fw notifier[8274]: successfully processed request for notification
    2020:02:12-21:13:24 ng_fw postfix/pickup[4970]: 709972294B: uid=0 from=<do-not-reply@fw-notify.net>
    2020:02:12-21:13:24 ng_fw postfix/cleanup[8277]: 709972294B: message-id=<7031-08274-1581534803@ng_fw>
    2020:02:12-21:13:24 ng_fw postfix/qmgr[30597]: 709972294B: from=<do-not-reply@fw-notify.net>, size=1331, nrcpt=1 (queue active)
    2020:02:12-21:13:24 ng_fw postfix/smtp[8280]: 709972294B: to=<xxxxxxradu@yahoo.com>, relay=localhost[127.0.0.1]:25, delay=0.46, delays=0.33/0.13/0/0.01, dsn=2.0.0, status=sent (250 OK id=1j1xRs-00029Z-2R)
    2020:02:12-21:13:24 ng_fw postfix/qmgr[30597]: 709972294B: removed
    2020:02:12-21:14:37 ng_fw notifier[8384]: processing notification request for CRIT-861
    2020:02:12-21:14:37 ng_fw notifier[8384]: not sending CRIT-861 - over limit (0)
    2020:02:12-21:14:37 ng_fw notifier[8384]: successfully processed request for notification
    2020:02:12-21:14:40 ng_fw notifier[8396]: processing notification request for WARN-070
    2020:02:12-21:14:40 ng_fw notifier[8396]: not sending WARN-070 - over limit (0)
    2020:02:12-21:14:40 ng_fw notifier[8396]: successfully processed request for notification
    2020:02:12-21:15:25 ng_fw notifier[8617]: processing notification request for WARN-070
    2020:02:12-21:15:25 ng_fw notifier[8617]: not sending WARN-070 - over limit (0)

     

    I don't understand if these refer to the license expirations. I have not received any mail about it.

    Please tell me, where and how do i activate my notifications, like you mentioned?

     

    Thanks

    R

  • It looks like the INFO-020 notifications cannot be disabled, Radu, so you only need to make sure your email address is listed on the 'Global' tab of 'Management >> Notifications'.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

     

    My address is listed on the recipients list. However, check the photo attached: is the sender address ok ? what does the "limit notifications" check do ?

     

     

    R

  • 2020-MAR-09: CORRECTED 010 to 020 below

    That looks perfect, Radu.  Do you get any lines from the following?

    zgrep 'INFO\-020' /var/log/notifier/2020/02/*

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • hi,

     

    yes, i have these ones:

     

    /var/log/notifier/2020/02/notifier-2020-02-01.log.gz:2020:02:01-01:15:03 ng_fw notifier[2206]: processing notification request for INFO-010
    /var/log/notifier/2020/02/notifier-2020-02-08.log.gz:2020:02:08-01:15:03 ng_fw notifier[27057]: processing notification request for INFO-010
    /var/log/notifier/2020/02/notifier-2020-02-15.log.gz:2020:02:15-01:15:03 ng_fw notifier[8123]: processing notification request for INFO-010
    /var/log/notifier/2020/02/notifier-2020-02-22.log.gz:2020:02:22-01:15:03 ng_fw notifier[23025]: processing notification request for INFO-010
    /var/log/notifier/2020/02/notifier-2020-02-29.log.gz:2020:02:29-01:15:02 ng_fw notifier[7248]: processing notification request for INFO-010

  • Oops!  I corrected my post above.  In addition to the notifier log, you might also search the smtp log.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • yes, i see these lines in the smtp log:

     

    2020:02:21-08:37:29 ng_fw exim-out[1061]: 2020-02-21 08:37:29 1j4hhS-0006OI-CV mta5.am0.yahoodns.net [67.195.228.109]:25 Connection timed out
    2020:02:21-08:37:29 ng_fw exim-out[1060]: 2020-02-21 08:37:29 1j4hhS-0006OI-CV == xxxxxradu@yahoo.com R=dnslookup T=remote_smtp defer (110): Connection timed out
    2020:02:21-08:37:29 ng_fw exim-out[12112]: 2020-02-21 08:37:29 1j4T68-0007UE-Cf == xxxxxradu@yahoo.com R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
    2020:02:21-08:37:29 ng_fw exim-out[12114]: 2020-02-21 08:37:29 1j4fao-0002ml-6X == xxxxxradu@yahoo.com R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
    2020:02:21-08:37:29 ng_fw exim-out[12116]: 2020-02-21 08:37:29 1j4eyQ-0001RU-7q == xxxxxradu@yahoo.com R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host

     

    They don't look very good.

     

    R

  • What about

    zgrep 'INFO\-020' /var/log/smtp/2020/02/*

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA