<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Intermittent VPN Issues</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/127621/intermittent-vpn-issues</link><description>Hi, 
 One of our users has reported being unable to access one of the servers over the VPN, but only intermittently. 
 When they tried to ping the server they got &amp;quot;Request timed out&amp;quot; but soon after it started working again. I replicated this and saw two</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/470261?ContentTypeID=1</link><pubDate>Mon, 07 Jun 2021 15:07:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e21828e6-9284-4fcb-8c1d-8b11d4ad766a</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Ok, thanks for your quick reply. I will try to create a support case but from past experience I get much better support from you and your colleagues on here. I could wait weeks for a reply to a support case.&lt;/p&gt;
&lt;p&gt;However, it will be very difficult to do what you suggest and take a packet capture as the issue is intermittent and it is happening for a remote colleague so I don&amp;#39;t have control over the software.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Alan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/470260?ContentTypeID=1</link><pubDate>Mon, 07 Jun 2021 15:04:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dc9a964f-2fcc-4b7b-994c-bf233709867a</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;I think your original post only refers to the issue related to the &lt;strong&gt;ICMP&lt;/strong&gt; timeout, which is internally identified with&amp;nbsp;&lt;span&gt;the ID (&lt;/span&gt;&lt;strong&gt;NC-69286 -&amp;nbsp;ICMP times out when Firewall Acceleration is turned on&lt;/strong&gt;&lt;span&gt;). A fix for this issue would be tentatively included in firmware release 18.0 MR6.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;However, the issue with the communication on TCP ports 445 and 10444 might not be related to the firewall acceleration; I&amp;#39;d suggest you investigate this issue separately, take a packet capture when the issue occurs, if you don&amp;#39;t have a support case, open one for further investigation.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Thanks,&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/470258?ContentTypeID=1</link><pubDate>Mon, 07 Jun 2021 14:53:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8f4221be-cc27-47c7-9616-f1acde542cc6</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;, I&amp;#39;m just following up on my last message to make sure that you received it. This case should no longer be considered resolved.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/469795?ContentTypeID=1</link><pubDate>Tue, 01 Jun 2021 13:08:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:711dc1b7-5c2e-4b12-99fc-8720a2c1356d</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Hi Harsh,&lt;/p&gt;
&lt;p&gt;We had the need to reboot the UTM today for some electrical work and&amp;nbsp;soon after putting it back online I received a report from one of our users&amp;nbsp;that they couldn&amp;#39;t access one of the servers in the way described above.&lt;/p&gt;
&lt;p&gt;I verified that the firewall acceleration option is still disabled and after checking the logs I saw a corresponding message: &amp;quot;&lt;span&gt;Could not associate packet to any connection.&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This error message is reported on TCP ports&amp;nbsp;445 and&amp;nbsp;10444. Looking back through the logs, I can see similar errors from before our reboot so I think that can be discounted. However, I do see occurrences&amp;nbsp;of at least 445 being allowed. So it is a bit random.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;I would appreciate your feedback.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Regards,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Alan&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/468664?ContentTypeID=1</link><pubDate>Wed, 19 May 2021 13:21:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c7c4cfb5-6cea-4eaa-be33-c83ba3e8c214</guid><dc:creator>Alan Spark</dc:creator><description>[quote userid="81341" url="~/sophos-xg-firewall/f/discussions/127621/intermittent-vpn-issues/468663#468663"]I&amp;#39;d suggest you turn on the blog notification to get notified about the new releases &amp;amp; news here[/quote]
&lt;p&gt;Thanks, noted.&lt;/p&gt;
&lt;p&gt;Alan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/468663?ContentTypeID=1</link><pubDate>Wed, 19 May 2021 13:18:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b6959874-8dcf-4b54-a380-44e9aa12450a</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;This issue has been investigated internally with the ID (&lt;strong&gt;NC-69286 -&amp;nbsp;ICMP times out when Firewall Acceleration is turned on&lt;/strong&gt;). A fix for this issue would be tentatively included in firmware release 18.0 MR6.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The temporary workaround is to turn off the firewall acceleration.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;d suggest you turn on the blog notification to get notified about the new releases &amp;amp; news here:&amp;nbsp;&lt;a href="/sophos-xg-firewall/b/blog" rel="noopener noreferrer" target="_blank"&gt;Release Notes &amp;amp; News&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/468644?ContentTypeID=1</link><pubDate>Wed, 19 May 2021 11:06:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2e8395b1-628d-4132-bf60-8dad9e0b2597</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Hi Harsh,&lt;/p&gt;
&lt;p&gt;We have not experienced the issue again but&amp;nbsp;we feel that it is too soon to say for certain that it has been fixed. We&amp;#39;ll continue to monitor it.&lt;/p&gt;
&lt;p&gt;However, we would still like the issue to be fixed&amp;nbsp;so that we can enable the firewall acceleration option again.&lt;/p&gt;
&lt;p&gt;I note that&amp;nbsp;&lt;strong&gt;18.0.5 MR-5&lt;/strong&gt; is now available. I don&amp;#39;t see anything about this issue in it though?&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Alan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/468587?ContentTypeID=1</link><pubDate>Wed, 19 May 2021 03:04:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:42d23505-2fc3-497f-8408-953d967339a0</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Are you still experiencing the same issue with firewall acceleration turned off?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467943?ContentTypeID=1</link><pubDate>Tue, 11 May 2021 09:29:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:04a2faac-acad-4997-a86f-b628e72b4410</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Thanks. I don&amp;#39;t think this is the problem as there was nothing in the IPS logs. It wasn&amp;#39;t any particular port either, it seemed to be quite random.&lt;/p&gt;
&lt;p&gt;So far with the firewall acceleration disabled we&amp;#39;re not seeing the problem but as I said above, too early to draw conclusions.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467937?ContentTypeID=1</link><pubDate>Tue, 11 May 2021 08:29:12 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a3286bae-3b69-4596-b99a-2583c8b9cb21</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;Have you checked ThomW&amp;#39;s answer? If your VPN Protocol is UDP it is very likely that IPS/DoS Protection is pointing to your problem. You should review the IPS logs.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467925?ContentTypeID=1</link><pubDate>Tue, 11 May 2021 05:18:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1e4af7ac-e382-4ea2-8720-4268c7132bbe</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Hi Harsh,&lt;/p&gt;
&lt;p&gt;I was notified that your answer had been verified. This was not me.&lt;/p&gt;
&lt;p&gt;I have disabled firewall acceleration and we are monitoring it but I&amp;nbsp;think it is too soon to mark this as verified.&amp;nbsp;Even if it does &amp;quot;solve&amp;quot; the problem I would consider it a workaround as I don&amp;#39;t think it should be necessary to disable the option.&lt;/p&gt;
&lt;p&gt;We will continue to monitor over the coming days but in the meantime I have rejected your answer until we&amp;nbsp;have more information at this end.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Alan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467691?ContentTypeID=1</link><pubDate>Fri, 07 May 2021 14:04:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dd422dc9-dbb5-4398-8c82-7cb2cae38cb3</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;No problem, I&amp;#39;ve rejected the answer. :)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The firewall acceleration uses the advanced data-path&amp;nbsp;architecture allowing faster processing of data packets for known traffic.&lt;/p&gt;
&lt;p&gt;Check out this thread:&amp;nbsp;&lt;a href="/sophos-xg-firewall/f/discussions/123785/disabled-firewall-acceleration"&gt;https://community.sophos.com/sophos-xg-firewall/f/discussions/123785/disabled-firewall-acceleration&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can turn on the firewall acceleration with the following command:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;system firewall-acceleration enable&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467685?ContentTypeID=1</link><pubDate>Fri, 07 May 2021 13:28:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:528bf9b7-5204-4219-b7bc-c3bf41cf60fa</guid><dc:creator>ThomW</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I had kind of same problems on SG UTM while using VPN on UDP and DoS activated and solved by putting a exception for that port.&lt;/p&gt;
&lt;p&gt;Perhaps this is a problem wirh your XG configuration as well.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Thomas&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467678?ContentTypeID=1</link><pubDate>Fri, 07 May 2021 13:07:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:03c307ba-c005-44db-ba20-1048fc0d86b9</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Hi Harsh,&lt;/p&gt;
&lt;p&gt;I&amp;nbsp;think I accidentally marked your answer as verified - I don&amp;#39;t know how to undo it.&lt;/p&gt;
&lt;p&gt;Before we make this change, can you please explain what the feature does and any impact of disabling it?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Alan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467677?ContentTypeID=1</link><pubDate>Fri, 07 May 2021 12:44:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:844ba26e-c8a2-4ff2-89f6-dfa50294cfa5</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Thanks for the update!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Would it be possible for you to turn off the firewall acceleration, monitor the issue, and provide an update?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Run the following command to turn off the firewall acceleration:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;system firewall-acceleration disable&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;&lt;/em&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467649?ContentTypeID=1</link><pubDate>Fri, 07 May 2021 05:15:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:65260909-c516-4028-bfc7-d9f80071c1fb</guid><dc:creator>Alan Spark</dc:creator><description>&lt;p&gt;Hi Harsh,&lt;/p&gt;
&lt;p&gt;It is an XG 135 running&amp;nbsp;&lt;span&gt;SFOS 18.0.4 MR-4.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Here is the output from the command:&lt;/span&gt;&lt;/p&gt;
&lt;pre&gt;&lt;span&gt;console&amp;gt;&amp;nbsp;system&amp;nbsp;firewall-acceleration&amp;nbsp;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br /&gt;Firewall&amp;nbsp;Acceleration&amp;nbsp;is&amp;nbsp;Enabled.&lt;/span&gt;&lt;/pre&gt;
&lt;p&gt;&lt;span&gt;Regards,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Alan&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Intermittent VPN Issues</title><link>https://community.sophos.com/thread/467612?ContentTypeID=1</link><pubDate>Thu, 06 May 2021 18:23:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1fbac3dc-ffa4-4a6c-a4cb-d02c30db5044</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/alan-spark"&gt;Alan Spark&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Thank you for reaching out to the Community!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Could you please provide the model number and current firmware version of your firewall?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Is firewall acceleration turned on?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Please run the following command from the console and provide the output:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;system firewall-acceleration show&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://support.sophos.com/support/s/article/KB-000038697?language=en_US" rel="noopener noreferrer" target="_blank"&gt;Sophos XG Firewall: How to SSH to the firewall using PuTTY utility&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Type&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;4&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;to access the&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Device console&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>