Hi all,
Shall we start this new thread with the looks and feels of XG v18 MR-3?
community.sophos.com/.../xg-firewall-v18-mr3
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
Hi all,
Shall we start this new thread with the looks and feels of XG v18 MR-3?
community.sophos.com/.../xg-firewall-v18-mr3
Do you use STAS? Sounds like the log off detection (STAS Quarantine) is hitting in your case.
https://support.sophos.com/support/s/article/KB-000035623?language=en_US
If you use STAS, select:
If this is not matching your Issue. Please open another Thread to keep the visibility here.
__________________________________________________________________________________________________________________
Thanks LuCar Toni. I clearly don't learn because you resolved exactly the same problem for me at our own site about a year ago. Now made big notes on our STAS documentation. I find it difficult to understand why the default is 'yes'. It is more secure but who on earth would want to have their internet traffic stopped for a couple of minutes every few hours? Had only one drop in nearly a week. That was after an IPS definition update so i suspect a different issue and am monitoring to see if that is a recurring problem. Will follow up in a new post if it is.
Hi All, here is the config which is set. The UTM is not problem at all but the XG just will not stay pinned up.
here is the Draytek 2862 config, I have tried both IKEv1 and IKEv2 both have the same problem.
also the IKE phase 2 key lifetime is set at 28800 as support asked me to change it
Here is the XG v18 MR3 policy
support are looking at it, but there is not much in the way of a fix only one comment, and trying to wait for them to get back is becoming tedious.
any help appreciated.
XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)
Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!
Do we talk about Route based VPN or Policy based Tunnels? Do you have standalone or HA appliance? Which Size?
Giridhar Katti / FloSupport could we look into this?
__________________________________________________________________________________________________________________
Hi Argo
Most of your settings are the same as mine, with the exception of some of the timeout values.
The main difference I can see is in your IPSec policy - Dead Peer Detection. If I understand correctly, with no traffic, this will cause your VPN to disconnect. Maybe try disabling and see if that resolves your problem.
BTW, I feel your pain with Sophos Support - I can't get Radius authentication to work across my VPNs since replacing a Sonicwall with an XG. Response from support has been appalling!