This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.0 GA: Feedback and experiences

Parents
  • Upgraded our XGS5500 Cluster this weekend to v19ga. Now we've got some serious problems with our IPSec Site to Site connections. Those connections are setup as tunnel connections with xfrm interfaces. We use BGP over those interfaces. The problem is that connectivity between our branch routers (XG125) and the main router for those tunnels is down every 30-50 minutes. VPN Tunnel is still up but the xfrm interfaces cant reach eachother. The only thing that is working is disableing the hole ipsec tunnel and reenabling it. Only then the xfrm interfaces can reach eachother for some time. I allready opened a support ticket but maybe some around here has had the same issue and a quick fix for me.

  • Have you checked the ipsec guide? DPD should only enabled on vpn initiator and phase 1 and phase 2 re-key shouldn't happen at same time. Maybe this is your problem?

Reply Children