This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot access intranet websites over VPN.

We are using OpenVPn on our Sophos firewall. Yesterday I upgraded from SFOS 18.0.5 MR-5-Build586 to SFOS 19.0.0 GA-Build317.

We have a number of intranet websites running in docker containers on a single server. After the upgrade they are fully accessible through the intranet, the server and docker containers are all up and running fine.

Before the upgrade, the intranet websites could all be accessed over OpenVPN. After the upgrade they cannot.

The logs report that the relevant firewall rule is working fine and allowing access. They show 1 packet incoming and 1 packet outgoing on the connections.

Using wget to test the website, I get the error "Connection refused."

TCP dump on the docker server shows no packets at all.

PCAP on the firewall shows a SYN packet incoming and an RST packet outgoing.

The problem happens with both port 80 and port 443 connections.

All other OpenVPN traffic is fine (ping, SSH, VNC).

Does anyone have any clues?



This thread was automatically locked due to age.
Parents
  • Hi Dynautics IT Admin,

    I hope you have taken the backup before upgrading the firmware version to the latest?

    Have you reverted back the firmware to SFOS 18.0.5 MR-5-Build586 ? and service got restored?

    Thanks and Regards 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Umm. To be honest I'm not a proper IT Admin and do this part time from my main role, and no...

    Logs show the last backup failed. I didn't explicitly run a backup before upgrading.

    I haven't reverted the firmware because I am not in the office which I need to be in case something goes wrong (I had to manually power cycle during the upgrade because the automatic reboot seemed to hang). Also, by now most of the employees are all logged in remotely over VPN so I can't afford to take the firewall down.

    On the very rare occasions I have done an upgrade on the firewall before, it just worked (TM), and I was expecting this one too as well. I feel like an idiot now, but like I say, this isn't what I do all day every day. I'm a software engineer, not an IT guy!

  • Hi Dynautics IT Admin

    Better you raise the case with Sophos Support team and try to reach via call or chat support with below link as access  to Sophos XG firewall is required to check the current configuration and to look into the workaround  : 

    https://support.sophos.com/support/s/?language=en_US#t=AllTab&sort=relevancy

    Thanks and Regards

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data