Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Version 19.0.0GA Breaking IPSEC VPN's

We have 20+ Xg and XGS's deployed. We started pushing out the mentioned version updating from 18.5.3 MR-3 Build 408. The first 2 devices we updated had all kinds of VPN issues. Users could connect but the connection speed was garbage (less than 1mbps down). Was on the phone with support for over an hour. Finally they came back and said "after conferring with his colleagues there are issues with Version 19 we recommend you rollback". We did this and all the VPN issues were resolved.

FRUSTRATING to say the least. I have reached out to our Sophos Rep regarding this and updates moving forward but so far "Crickets"



This thread was automatically locked due to age.
Parents
  • Just want to add our experience - tired to talk to Sophos Support !

    Customer all XGS 136 with IPSec VPN Site to Site - same issues as listed and discussed here! What we all tried but still get not better:

    - Disable IPS

    - Change MTU (1500 -> 1492) and MSS (1429)

      -> community.sophos.com/.../issue-of-mss-on-ipsec-vpn

      -> https://www.cisco.com/c/de_de/support/docs/ip/generic-routing-encapsulation-gre/25885-pmtud-ipfrag.html

      -> www.sonicwall.com/.../

    - Change IPSec Profile AES256 to AES192

    - Enable Compressed Data

    - Check if IPSec Acceleration is disabled

    console> system ipsec-acceleration show
    IPsec acceleration status: turned off

    - Check if Firewall Acceleration is disabled - Thanks to LuCar Toni - That was still enabled!

    console> system firewall-acceleration show
    Firewall Acceleration is Enabled in Configuration.
    Firewall Acceleration is Loaded.
    console> system firewall-acceleration disable
    Firewall Acceleration Disabled Successfully.

    With the Tip from LuCar looks to be working now - My last question: When we expect 19.0.2 with the fix to be GA?

    Expert-Zone.Net IT Consulting
    Neuenhofer Weg 23 • D-52074 Aachen



    Thanks to LuCar Toni !
    [edited by: n.coker at 1:11 PM (GMT -8) on 11 Nov 2022]
Reply
  • Just want to add our experience - tired to talk to Sophos Support !

    Customer all XGS 136 with IPSec VPN Site to Site - same issues as listed and discussed here! What we all tried but still get not better:

    - Disable IPS

    - Change MTU (1500 -> 1492) and MSS (1429)

      -> community.sophos.com/.../issue-of-mss-on-ipsec-vpn

      -> https://www.cisco.com/c/de_de/support/docs/ip/generic-routing-encapsulation-gre/25885-pmtud-ipfrag.html

      -> www.sonicwall.com/.../

    - Change IPSec Profile AES256 to AES192

    - Enable Compressed Data

    - Check if IPSec Acceleration is disabled

    console> system ipsec-acceleration show
    IPsec acceleration status: turned off

    - Check if Firewall Acceleration is disabled - Thanks to LuCar Toni - That was still enabled!

    console> system firewall-acceleration show
    Firewall Acceleration is Enabled in Configuration.
    Firewall Acceleration is Loaded.
    console> system firewall-acceleration disable
    Firewall Acceleration Disabled Successfully.

    With the Tip from LuCar looks to be working now - My last question: When we expect 19.0.2 with the fix to be GA?

    Expert-Zone.Net IT Consulting
    Neuenhofer Weg 23 • D-52074 Aachen



    Thanks to LuCar Toni !
    [edited by: n.coker at 1:11 PM (GMT -8) on 11 Nov 2022]
Children