This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec VPN keeps down after DSL lines reconnects...

i run several ipsec tunnel for years without any problems... all runs fine with 9.355-1


since the update to 9.402-7 all ipsec tunnels are down every morning.


i checked the ipsec-logs and found out that after my dsl-lines reconnect the tunnels will not come up again.

i have to turn them off and on and then all works....


anyone can help?



This thread was automatically locked due to age.
  • PUSH!


    need help... please sophos staff seems to be a bug..

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • I spend several hours to the same problem

    Site 1: SG135 Appliance 9.402-7 (initiate connection)

    Site 2: UTM120 Appliance 9.402-7 (listen)

    Same Problem, Site-to-Site IPSec works with 9.355-1 and is broken every morning after DSL reconnect since update to 9.402-7

    Update to 9.402-7 was scheduled to night of 2016/05/11 to both appliances, one on 3:00 the second on 4:00 and since this update the VPN tunnel fails to come up again after reconnect  DSL line.

    It's not 100% possible to bring up the tunnel again with manunal switch off and on again the IPSec connection.

    Sometimes it helps to stop/start the IPSec connection, but sometimes it works, somtimes I have to reconnect 1-5 times and sometimes the connection doesn't come up again after 10 tries

    My way to bring back the tunnel: restart UTM every morning before working hours ...

    You can force the problem if you do a "reconnect" on the Interface (for me: ETH1 ADSL with static IP) which uses the IPSec Site-to-Site connection. After a reconnect the VPN tunnel stays down

    Workaround for me since serveral debug tries with the log file entries show no solutions for me:

    Site 1: go back to 9.355-1 (download 9.355-1 ISO , new install and use a  backup .abf to get to the former state)

    Since this rollback to 9.355-1 the IPSec Site-to-Site VPN tunnel works with no problems like the years before

    any help? 

  • We have the same problem. My workaround every morning is. In the Debug Tab activate something and save it. Then turn it of an save it again and all VPNs are working.

  • Hi,

    Please post IPsec logs. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Here are some logs from my life production system:


    i have pressed "reconnect" on a dsl line (DSL16K_1). got 2 IPSEC Tunnels on this interface (S_VPN_EC and S_VPN_UHAB). both going down and will not come up again.

    2016:05:23-15:03:10 vpn-1 pluto[5152]: shutting down interface ppp0/ppp0 80.153.47.40
    2016:05:23-15:03:10 vpn-1 pluto[5152]: shutting down interface ppp0/ppp0 80.153.47.40
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_UHAB" #22: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_UHAB" #22: sendto on ppp0 to 193.159.189.99:500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_UHAB" address="80.153.47.40" local_net="10.2.128.0/23" remote_net="192.168.12.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_UHAB" address="80.153.47.40" local_net="10.2.128.0/23" remote_net="192.168.12.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_UHAB" #2: deleting state (STATE_MAIN_I4)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_UHAB" #2: sendto on ppp0 to 193.159.189.99:500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: /sbin/ip -4 route del 192.168.12.0/24 dev ppp0 src 10.2.128.10 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC" #30: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #30: sendto on ppp0 to 91.6.233.166:4500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.10.30.0/24" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.10.30.0/24" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC" #31: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #31: sendto on ppp0 to 91.6.233.166:4500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.2.128.0/23" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.2.128.0/23" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: shutting down interface ppp0/ppp0 80.153.47.40
    2016:05:23-15:03:10 vpn-2 pluto[32759]: shutting down interface ppp0/ppp0 80.153.47.40
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC" #32: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #32: sendto on ppp0 to 91.6.233.166:4500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: /sbin/ip -4 route del 192.168.12.0/24 dev ppp0 src 10.2.128.10 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.35.0.0/16" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC" #33: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #33: sendto on ppp0 to 91.6.233.166:4500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.41.10.0/24" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC" #1: deleting state (STATE_MAIN_I4)
    2016:05:23-15:03:10 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #1: sendto on ppp0 to 91.6.233.166:4500 failed in delete notify. Errno 22: Invalid argument
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC" #32: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-2 pluto[32759]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.35.0.0/16" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-1 pluto[5152]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: forgetting secrets
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:03:10 vpn-1 pluto[5152]: listening for IKE messages
    2016:05:23-15:03:10 vpn-1 pluto[5152]: forgetting secrets
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:23-15:03:10 vpn-1 pluto[5152]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:23-15:03:10 vpn-1 pluto[5152]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC" #33: deleting state (STATE_QUICK_I2)
    2016:05:23-15:03:10 vpn-1 ipsec_starter[13631]: no default route - cannot cope with %defaultroute!!!
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-1 pluto[5152]: "S_VPN_2_UHAB": deleting connection
    2016:05:23-15:03:10 vpn-2 pluto[32759]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="VPN_2_EC" address="80.153.47.40" local_net="10.41.10.0/24" remote_net="192.168.0.0/24"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC" #1: deleting state (STATE_MAIN_I4)
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: /sbin/ip -4 route del 192.168.0.0/24 dev ppp0 src 10.41.10.1 proto ipsec metric 0 failed with status 1:
    2016:05:23-15:03:10 vpn-2 pluto[32759]: updown: Cannot find device "ppp0"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: forgetting secrets
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:03:10 vpn-2 pluto[32759]: HA System: not master, won't listen for IKE messages
    2016:05:23-15:03:10 vpn-2 pluto[32759]: forgetting secrets
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:23-15:03:10 vpn-2 pluto[32759]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:23-15:03:10 vpn-2 ipsec_starter[28193]: no default route - cannot cope with %defaultroute!!!
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_EC": deleting connection
    2016:05:23-15:03:10 vpn-2 pluto[32759]: "S_VPN_2_UHAB": deleting connection
    2016:05:23-15:04:12 vpn-1 pluto[5152]: adding interface ppp0/ppp0 80.153.47.40:500
    2016:05:23-15:04:12 vpn-1 pluto[5152]: adding interface ppp0/ppp0 80.153.47.40:4500
    2016:05:23-15:04:12 vpn-1 pluto[5152]: forgetting secrets
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.153.47.40 193.159.189.99
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.153.47.40 rtrec01.wiesbaden.c-ernst.de
    2016:05:23-15:04:12 vpn-1 pluto[5152]: listening for IKE messages
    2016:05:23-15:04:12 vpn-1 pluto[5152]: forgetting secrets
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.153.47.40 193.159.189.99
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded PSK secret for 80.153.47.40 rtrec01.wiesbaden.c-ernst.de
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:23-15:04:12 vpn-1 pluto[5152]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:23-15:04:12 vpn-1 pluto[5152]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:23-15:04:12 vpn-1 ipsec_starter[13631]: no default route - cannot cope with %defaultroute!!!
    2016:05:23-15:04:12 vpn-1 pluto[5152]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: "S_VPN_2_EC" #36: initiating Main Mode
    2016:05:23-15:04:12 vpn-1 pluto[5152]: ERROR: "S_VPN_2_EC" #36: sendto on ppp0 to 91.6.233.166:500 failed in main_outI1. Errno 1: Operation not permitted
    2016:05:23-15:04:12 vpn-1 pluto[5152]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: added connection description "S_VPN_2_UHAB"
    2016:05:23-15:04:12 vpn-1 pluto[5152]: "S_VPN_2_UHAB" #37: initiating Main Mode
    2016:05:23-15:04:12 vpn-2 pluto[32759]: adding interface ppp0/ppp0 80.153.47.40:500
    2016:05:23-15:04:12 vpn-2 pluto[32759]: adding interface ppp0/ppp0 80.153.47.40:4500
    2016:05:23-15:04:12 vpn-2 pluto[32759]: forgetting secrets
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.153.47.40 193.159.189.99
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.153.47.40 rtrec01.wiesbaden.c-ernst.de
    2016:05:23-15:04:12 vpn-2 pluto[32759]: HA System: not master, won't listen for IKE messages
    2016:05:23-15:04:12 vpn-2 pluto[32759]: forgetting secrets
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading secrets from "/etc/ipsec.secrets"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 213.33.54.4
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.153.47.40 193.159.189.99
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 82.194.122.60
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.147.189.220 91.67.35.176
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded PSK secret for 80.153.47.40 rtrec01.wiesbaden.c-ernst.de
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:23-15:04:12 vpn-2 pluto[32759]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:23-15:04:12 vpn-2 pluto[32759]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:23-15:04:12 vpn-2 ipsec_starter[28193]: no default route - cannot cope with %defaultroute!!!
    2016:05:23-15:04:12 vpn-2 pluto[32759]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: added connection description "S_VPN_2_EC"
    2016:05:23-15:04:12 vpn-2 pluto[32759]: added connection description "S_VPN_2_UHAB"

    only way to get them up again:

    shut down ALL IPSEC-Tunnels and get them on again (also the ones not on the reconnecting interface) or to turn some debug on and off (which results in an ipsec restart i think...

    hope that helps you to find the error...

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • I have the same problem since updating to 9.402-7. I have 3 Uplink Interfaces (1 DSL, 2 Static IP). The IPsec Tunnel connects to the DSL-Line. After the daily DSL disconnect the IPsec-Tunnel doesn't come up again. When I disable the two other interfaces and then disable/enable the IPsec connections, the tunnel comes up and i can enable the two other interfaces again. Looks like the IPsec doesn't "know" which interface should be used as gateway.
  • Hi everybody,

    I have the same problem since the last update. Every morning my VPNs are down. Very annoying. :(

    Hope there will be a fix soon.

  • Same Problem here with two UTMs and two VDSL lines, one might be an ADSL.

    Are you guys using a Zyxel router as your VDSL Modem? A customer mentioned an forum post were this was an issue with the modem firmware and the new utm update. I couldnt update the Zyxel Modem yet to test.

    I changed the s2s tunnel from PSK to Cert, that didn't help either, the customer said the only way to bring the tunnel up is to reboot the UTM in HQ were the VDSL line is.

    Both sides are working through an dyndns account and do not have static IPs as far as I know

    The logs are kinda quiet, not a lot going on in my opinion?!

    HQ:

    2016:05:26-22:11:16 vpn pluto[6362]: forgetting secrets
    2016:05:26-22:11:16 vpn pluto[6362]: loading secrets from "/etc/ipsec.secrets"
    2016:05:26-22:11:16 vpn pluto[6362]: loaded private key from 'Local X509 Cert.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: listening for IKE messages
    2016:05:26-22:11:16 vpn pluto[6362]: forgetting secrets
    2016:05:26-22:11:16 vpn pluto[6362]: loading secrets from "/etc/ipsec.secrets"
    2016:05:26-22:11:16 vpn pluto[6362]: loaded private key from 'Local X509 Cert.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:26-22:11:16 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/vpn-badsaulgau-ebersbach Verification CA 1.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/owa.alu-line-de Verification CA 1.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/owa.alu-line-de Verification CA 2.pem'
    2016:05:26-22:11:16 vpn pluto[6362]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:26-22:11:16 vpn pluto[6362]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:26-22:11:16 vpn pluto[6362]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:26-22:11:16 vpn pluto[6362]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:26-22:11:16 vpn ipsec_starter[6343]: no default route - cannot cope with %defaultroute!!!
    2016:05:26-22:11:16 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL": deleting connection
    2016:05:26-22:11:16 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL" #233: deleting state (STATE_MAIN_I1)
    2016:05:26-22:11:16 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL": deleting connection
    2016:05:26-22:11:16 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL": deleting connection
    2016:05:26-22:12:48 vpn pluto[6362]: forgetting secrets
    2016:05:26-22:12:48 vpn pluto[6362]: loading secrets from "/etc/ipsec.secrets"
    2016:05:26-22:12:48 vpn pluto[6362]: loaded private key from 'Local X509 Cert.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: listening for IKE messages
    2016:05:26-22:12:48 vpn pluto[6362]: forgetting secrets
    2016:05:26-22:12:48 vpn pluto[6362]: loading secrets from "/etc/ipsec.secrets"
    2016:05:26-22:12:48 vpn pluto[6362]: loaded private key from 'Local X509 Cert.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loading ca certificates from '/etc/ipsec.d/cacerts'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/vpn-badsaulgau-ebersbach Verification CA 1.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/VPN Signing CA.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/owa.alu-line-de Verification CA 1.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded ca certificate from '/etc/ipsec.d/cacerts/owa.alu-line-de Verification CA 2.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loading aa certificates from '/etc/ipsec.d/aacerts'
    2016:05:26-22:12:48 vpn pluto[6362]: loading ocsp certificates from '/etc/ipsec.d/ocspcerts'
    2016:05:26-22:12:48 vpn pluto[6362]: loading attribute certificates from '/etc/ipsec.d/acerts'
    2016:05:26-22:12:48 vpn pluto[6362]: Changing to directory '/etc/ipsec.d/crls'
    2016:05:26-22:12:48 vpn ipsec_starter[6343]: no default route - cannot cope with %defaultroute!!!
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/Local X509 Cert.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/REF_IpsX509.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: added connection description "S_VPN_Ebersbach-VDSL"
    2016:05:26-22:12:48 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL" #234: initiating Main Mode
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/Local X509 Cert.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/REF_IpsX509.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: added connection description "S_VPN_Ebersbach-VDSL"
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/Local X509 Cert.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: loaded host certificate from '/etc/ipsec.d/certs/REF_IpsX509.pem'
    2016:05:26-22:12:48 vpn pluto[6362]: added connection description "S_VPN_Ebersbach-VDSL"
    2016:05:26-22:25:58 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL" #234: max number of retransmissions (20) reached STATE_MAIN_I1. No response (or no acceptable response) to our first IKE message
    2016:05:26-22:25:58 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL" #234: starting keying attempt 2 of an unlimited number
    2016:05:26-22:25:58 vpn pluto[6362]: "S_VPN_Ebersbach-VDSL" #235: initiating Main Mode to replace #234

    ------------------------------------------------------------------------------------

    Remote site:

    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: received Vendor ID payload [strongSwan]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: ignoring Vendor ID payload [Cisco-Unity]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: received Vendor ID payload [XAUTH]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: received Vendor ID payload [Dead Peer Detection]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: received Vendor ID payload [RFC 3947]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
    2016:05:26-22:28:28 gw2 pluto[1723]: packet from 93.222.132.44:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
    2016:05:26-22:28:28 gw2 pluto[1723]: "S_VPN_BadSaulgau" #29: responding to Main Mode
  • Are you guys use multipathing? I can only bring the tunnel back up when I reboot the UTM in HQ, that UTM has two Uplinks, one ADSL and one VDSL, the VDSL is used for the ipsec and has an dynamic IP (Telekom DSL)

    psec_starter[13631]: no default route - cannot cope with %defaultroute!!!

    https://community.sophos.com/products/unified-threat-management/f/58/p/77077/297383#297383

  • I also use multipathing. I have a 30 day trial SG135 which is used as my productive system and my old UTM120 which is used as testsystem to try the 9.403, so I can try some configs.

    Ext. Interface - Telekom ADSL, static IP (used for IPsec site2site vpn)

    Ext. Interface1 - 2. Telekom ADSL, static IP

    Ext. Interface2 - m-net ADSL, dynamic IP

    I tried to config it like described in the Sophos knowledgbase ID 118975

    https://www.sophos.com/de-de/support/knowledgebase/118975.aspx

    I have only a 1:1 IPsec connection, but I tried not to use my Ext. Interface but the Uplink Interfaces and added a multipath rule on top: BranchOfficeNetwork --> Any Service --> MyInternal Network --> by connection    --  Balanced to: Uplink Interfaces

    --> It also worked - until I did a "reconnect" on my Ext.Interface

    The only way to bring the tunnel back without a UTM restart is to change the last ribbon in the IPsec section (Fehlersuche) and change one of the debug level checkboxes. This brings back the tunnel after a reconnect.

    My productive system stays on 9.355 since no solution until no ...