Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Version 19.0.0GA Breaking IPSEC VPN's

We have 20+ Xg and XGS's deployed. We started pushing out the mentioned version updating from 18.5.3 MR-3 Build 408. The first 2 devices we updated had all kinds of VPN issues. Users could connect but the connection speed was garbage (less than 1mbps down). Was on the phone with support for over an hour. Finally they came back and said "after conferring with his colleagues there are issues with Version 19 we recommend you rollback". We did this and all the VPN issues were resolved.

FRUSTRATING to say the least. I have reached out to our Sophos Rep regarding this and updates moving forward but so far "Crickets"



This thread was automatically locked due to age.
Parents
  • Hi everyone

    We had the same problem on XG (cloud one)
    So no ipsec acceleartion available
    No firewall acceleration available 

    Yesterday i upgraded in v19.01
    And still the same issue

    Force to rollback in 18.04...

    Any fix ?

  • Try disable firewall acceleration. 

    __________________________________________________________________________________________________________________

  • I did it yesterday but not worked
    And when i type in : console firewall-acceleration show

    Tell me that is a virtualised firewall so no firewall-acceleration available
    And no ipsec acceleration too

  • Hi there,

    have had some cases open regarding this. One customer with XG450 has big impact on his business, from time to time. Issue started with v19.0.

    Sophos support has told me, that performing following commands could help for non XGS devices:

    console> system ipsec-acceleration enable
    console> system ipsec-acceleration disable

    You will get this message:
    IPsec acceleration isn't available on XG Series hardware, virtual, software, and cloud devices.

    But support says: Issuing these commands helped a lot of customers, when they faced issues. This "knowledge" is pretty new to them, they say.

    Give it a try.

  • Hi,

    I'll give it a try in non-working hour and keep you updated.

    Thanks

  • Hello,

    I tried this solution  yesterday when upgrading to v19.5.0

    Sophos support has told me, that performing following commands could help for non XGS devices:

    console> system ipsec-acceleration enable
    console> system ipsec-acceleration disable

    You will get this message:
    IPsec acceleration isn't available on XG Series hardware, virtual, software, and cloud devices.

     

    But we have still the same problem.
    I explain, we can connect to Sophos Connect without problem, and access to every ressources that are attached to the firewall that host the VPN Remote Access

    But when we want to access ressources connected in IPSEC VPN Site to site it's not working.

    That's weird because ping is ok and DNS resolution too.

    But every other services are not working (SSH, SMB, HTTP/S... etc), there are authorized in the rules

    Here a schema to explain


    So I rolled back to 18.5.3 and it's working

  • Could you try to disable the Firewall acceleration? 

    __________________________________________________________________________________________________________________

  • I did it yesterday but not worked
    And when I type in : console firewall-acceleration show

    Tell me that is a virtualised firewall so no firewall-acceleration available
    And no ipsec acceleration too

  • That is odd to me. 

    Azure Firewall: 

    Sophos Firmware Version: SFOS 19.5.0 GA-Build197
    Model: SFV6C8


    console> system firewall-acceleration show
    Firewall Acceleration is Enabled in Configuration.
    Firewall Acceleration is Not Loaded because Device is Not Supported.
    console>

    __________________________________________________________________________________________________________________

Reply
  • That is odd to me. 

    Azure Firewall: 

    Sophos Firmware Version: SFOS 19.5.0 GA-Build197
    Model: SFV6C8


    console> system firewall-acceleration show
    Firewall Acceleration is Enabled in Configuration.
    Firewall Acceleration is Not Loaded because Device is Not Supported.
    console>

    __________________________________________________________________________________________________________________

Children