Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Microsoft Always On VPN dropping when through Sophos XG 330

Hey

I've been tasked with migrating away from the Sophos SSL VPN Client to Microsofts new Always On VPN (DA replacement). I've deployed all the servers and have them all configured and running, MS RRAS and MS NPS servers, secured with certificates and everything is running well, however after anything from 10 minutes to 4 hours the VPN states its connected but no traffic passes from the PC/laptop to the internal LAN.

The reason I query the Sophos XG is because if I direct the traffic through an old Sonicwall I don't get any traffic stopping.

From all the documentation as it's IKEv2 I only need to forward UDP 500 and UDP 4500 from WAN to RRAS in DMZ- does anyone have any experience, is this enough, am I missing something?

Disconnect and reconnect VPN and it comes back online for the next 10 minutes to 4 hours!

 

Any advice would be greatly appreciated.



This thread was automatically locked due to age.
Parents Reply
  • Thanks Keyur, I will get the capture done, couldbe slightly tricky since I can't access the firewall once the VPN drops the traffic but will think of a way to get in and sort it - should happen at somepoint in the next 4 hours!

     

    Re: NPS firewall, I've disabled while testing and it's not made an difference, also the same NPS server handles the traffic fine when the connection comes through to a RRAS behing the Sonicwall.

     

    Let me come back to you with the packet capture.

     

    Cheers

     

    Arron 

Children
No Data