I'm experiencing sudden break ups witht he connection with my XG135w.
The configuration is as follows: ISP model with optical connection - unmanaged switch (with nothing else connected except ISP modem and XG) - XG - couple of switches with PoE and two Ubiquiti AP.
It all started on friday last week when I wanted to configure my two Ubiquiti APs with additional Guest WiFi network (with our existing one). After that the Ubiquiti APs started breaking up, so I deleted the newly created Guest WiFi, but after this I realised that our XG is always breaking up the connection to the internet. COuple of times it was WAN interface down, then it was okay but the connection was just broken for couple of seconds (without messaging that the WAN is down), then it went up for another couple of minutes, than breaks and so on (often with the message DNS_PROBE_FINISHED_NXDOMAIN after trying to refresh a site or to open a new one).
We have a ESXi on the network that has a AD virtual machine. The XG has a static DNS IP address set.
I'm not sure where to look at. It was all running smoothly before this Ubiquiti thing. Tried one more time to play with MTU (it was 1500) or to add a second rule to the WAN link manager for going down, but without help.
here are the pictures of the setting:
And the screenshot of the CLI (I've run the command "cat dgd.log |grep dead")
Hey Shteki,Thank you for the update, use global DNS 188.8.131.52 in DNS 1 preference following with the mentioned one. Under the WAN Link manager under the failover gateways > edit the failover rules and with the "AND" condition also add your interface gateway too.Observe this and see if that has improved the situation.
Thanks & Regards,_______________________________________________________________
Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved
Sophos Community | Product Documentation | Sophos Techvids | SMSIf a post solves your question please use the 'Verify Answer' button.
you mean something like this:
Yup Shteki, that's right !!
I've changed it, I'm going to bserve it during the next couple of hours and reply here with the result.
Sure, and have you also updated the DNS preference under the DNS section ? As per the screenshot the DNS 1 preference is set to 10.27.27.6 , So would suggest keep the global DNS 184.108.40.206 as DNS 1 and following with that DNS 2 as 10.27.27.6 !! Shteki
Thank you, I've just updated this too, going to see is it going to help.
Sure, you're welcome !!
sadly, I didn't help, my colleagues told me that for the last hour they had 4 short breakdowns...
Breakdown - WAN link, right ?
The WAN doesn't report now breaking up, but the internet connection is breaking up all the time. The colleagues see when their site suddenly stops loading or if they have a VPN connection to another external site and the connection just hangs up.
Hello Shteki, So any authentication method used for the users who are facing the disconnection ? How many number of users are impacted ? Can you share the complete graph from the diagnostics > system graph...
all of the users are impacted, everyone that is on the network, either over WLAN or wired. The problem is still there.
Here are the screenshots:
You faced the issue in last two hours or before that ? Shteki
We had the issues also i n the last couple of hours
Couple or exactly 2 hours, cause the reports is show for last 2 hours, I would suggest generate it for last 24 hours !!
here is for the last 48 hours:
Memory/CPU looks fine, but the WAN data transfer seems to be on a peak when the issue occurs !! What type of authentication is being used for the users to access internet ?Under the FW rule , do you use web/app/IPS or scanning ?
There is no real authentification, as son as you connect to any of the outlets in the office or via WiFi, you have the ability to access internet.
Regarding FW rule, I need to check this one and give an edit.
Please check and perform a packet capture from the diagnostics to see if it is not causing any violation !!
Just checked the web/app/IPS, everything okay, like it was before when it worked (for two years), no changes.
I've started packet capture, going to check, when the first break apperas, what is says.
Could it be with dynamic DNS? We had some problems with it a while ago (two months), it would break the connections, but that it worked for some time.
May be may be not, let's perform a packet capture during the break from the diagnostics.From the CLI, check for the drop-packet-capture: https://support.sophos.com/support/s/article/KB-000036858?language=en_USAnd also conntrack: https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/117389/sophos-xg-cli-troubleshooting-tools