Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Home Edition Sophos XG Basic WAN Routing Issues

I am seriously getting irritated with the Home Edition Sophos XG lately.

First, enabling WWAN broke the install. As soon as the server booted after enabling, no Ethernet devices would work. Not even a "factory reset" fixed it. I have to completely reinstall just to get networking back.

Now I am constantly having connection issues. Weather.com never works, google.com always works, just about every other website is hit or miss. I never get a Sophos page saying it was blocked. The DNS server on the device doesn't seem to function - so if I setup DHCP to configure 172.16.16.16 as DNS nothing resolves but internet somewhat works on 8.8.8.8 or 1.1.1.1 or the device's DNS.

What is really irritating is websites will work then won't. The router log shows "invalid traffic" without any "zones" being defined. And it masquerade settings or connection timeout isn't the issue since it will work then 5 minutes later it won't.

I have the most basic setup. Lan as default network 172.16.16.16/24 on port 1. Port 2 is another router at 192.168.5.1/24. Basic firewall routing that allows "All" apps and web.. I have also tried none and new ones I made. Bottom line, the connection is very unstable.

I use Sophos because I don't want any legal hassles from people I let use the network downloading off BitTorrent.. but other then that I don't really need such a system.

Been using Sophos XG for at least 3 years, I have configured just about everything there is, red, site2site ssl VPN, remote VPN, etc.. and here I'm not doing any of that.. it is an ultra basic setup and it still doesn't seem to work..

Any ideas?



This thread was automatically locked due to age.
Parents Reply Children
  • It ended up being the Solution at https://support.sophos.com/support/s/article/KB-000037984?language=en_US

    I thought I tried this before but it didn't seem to have been saved.. maybe I typed the command wrong..

    I should have checked the setting

  • Nevermind this only fixed it for like a week..

  • Since it the HotFix increasing the TCP timeout to over 3 hours .... I do not know how to help with "new" connections.
    Try to Disable SSL Completely (for Testing Only).
    Possible, the SSL-Exceptions are the solution really.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Increasing the timeout of TCP should not fix anything. It is not to fix a problem, more likely to move the dropped invalid traffic to another client (which is not an issue in the first place). 

    You root cause is something else. The invalid traffic basically means, somebody does not want to talk to you, maybe because the packets are corrupted.

    Somehow i have the feeling your WWAN will mix up the connection / Interfaces on your appliance. Check on linux the MACs of the interface and check, if those are still the same.  

    __________________________________________________________________________________________________________________

  • Disable SSL? All sites now use SSL..

    This isn't a solution..

  • Again, something else is wrong.. it isn't Sophos but some magically corrupt packets?

    So why did a reset to factory defaults fix it?

    But that I expect this is a long term solution since I formatted and reinstalled just a few weeks ago..

  • Ok lets tackle this from a different perspective: If you enable TLS decryption, XG will manipulate the packet. 

    If the client or the server are not accepting those packets, they will close the connection. By closing the connection, most clients/server will burst a "I do not want to talk to you" packet, called finish/reset (FIN/RST). XG will pick up this traffic and drop (the multiple packets) of this as invalid traffic. This is what you actually seeing on the appliance. 

    So: the TLS decryption or the DPI engine, which is manipulating the traffic, is causing your client to drop the connection. 

    First of all: Try to disable the TLS Decryption engine: 

    Check if this helps in any case. 

    If not, there could be a routing issue. 

    Do you have SD-WAN Policy Based Routes? 

    __________________________________________________________________________________________________________________

  • "Disable SSL? ...this isn't a solution.."

    of course only a moment just to make sure that it is not SSL ...


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • So why did a reset to factory defaults fix it?

    Possible because a factory reset device has no active ssl-decryption...


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • I guess I disabled it this way..