We have a deployment from around 21 SD-RED 60 which are working fine.
Now I need to test something and want to deploy another SD-RED 60 which was also working fine in the past. But now the RED cannot open a Tunnel and the red.log shows the following.
I tested another RED which has the same issue.
Hello Silvio F ,Thank you for reaching out to the community, SD-RED 20 & SD-RED 60 uses TCP 3400 + UDP 3410. And under the logs we can see the SSL handshake is failing.Under the advance shell, you may check via: #telnet red.astaro.com 3400
Thanks & Regards,_______________________________________________________________
Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved
Sophos Community | Product Documentation | Sophos Techvids | SMSIf a post solves your question please use the 'Verify Answer' button.
I know, thats what this log is showing. I want to know why the ssl handshake is failing because it makes no sense to me. This RED was in use till a week ago without any problems. I have the same Issue with another RED which was also in a productive Environment but now has issues with the SSL Handshake.
I can connecto on 3400 to red.astaro.com
can you share the tcpdump on Port 3400 ?#tcpdump -nei any port 3400
What are you looking for exactly? As I mentioned above, there are 21 Reds in place, and if I dump for any Port 3400, there will be a lot of noise.
But now I´m perplexed. I changed the Gateway to an other IP for the Red and the tunnel is established. But this doesn't make any sense.
Thanks for reaching out to the Community and hope all is well.
Thanks for the information you have provided. May I suggest that if you are keen to pursue the ongoing issue, please open a ticket to have further check and investigated by an engineer. https://support.sophos.com/support/s/?language=en_US#t=AllTab&sort=relevancy Please select "For Critical Cases" if this is urgent and needs immediate assistance and already impacts operations.
Many thanks for your time and patience and thank you for choosing Sophos
Raphael AlganesCommunity Support Engineer | Sophos Technical SupportSophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS AlertsIf a post solves your question use the 'Verify Answer' link.