This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec VPN to Draytek do not reconnect randomly

Hi,

I have XGS-126 as IPSec VPN client, calling Draytek router as VPN server. I also tried to reverse sides, but the problem remains the same.

From time to time, very randomly, it might be once every 2-3 weeks, or even so frequently like 4 times in 1 hour, VPN tunnel drops and does not re-establish connection. Sometimes manually clicking the red VPN dot establishes connection, but sometimes not.

Sophos LOGS are not helping me to diagnose, just a lot of:

IKE message retransmission to <Draytek IP> timed out. Check if the remote gateway is reachable.

I have VPN Profile settings just mirrored, what's on Draytek side:

  • IKE Phase 1, Re-key connection = ON
  • DPD = ON
  • DPD check every: 60 seconds
  • DPD When Peer Unreachable = Re-initiate
  • Dos Protection = OFF
  • DoS & Spoof exceptions added for both IPs as source and destination

When there was Draytek - Draytek VPN, on the same lines, VPN was rock-stable, never ever had problems.

Ideas welcome.



This thread was automatically locked due to age.
  • Hi  ,

    Good day and thanks for reaching out to Sophos Community and hope you are well.

    Few queries

    Was this previously working before and not having any issues?

    If yes,

    -does a firmware upgrade happened and then this issue occured (if yes-from which firmware to which firmware?)
    - was there any configuration changes on either ends? or any ISP change/downtime on either ends?

    Kindly check as well, if DPD policy is configured as Re-initiate:

    Additionally you may Kindly check this IPsec S2S Troubleshooting guide for issues: https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/VPN/SiteToSiteVPN/t_VPNIPsecSiteToSiteTroubleShootCommonErrors/index.html

    Hope this helps. Thanks for your time and patience and thank you for choosing Sophos

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Raphael,

    I am not sure if I reply in correct manner, as this forum design is strange to me (see below...I see duplicated reply, once only a part of it, then below again same reply, but in whole...don't get it, lol)

    Well, NO. VPN was working fine for few years with Drayteks on both sides, no problems ever. Then I added Sophos XGS-126 to one site and rewrote the IPSec VPN to reflact Draytek settings, and ever since it is dropping randomly. But it might even be up for few weeks without problems, or drop dozen times in one day, totally random.

    I will go through LOGS, following your troubleshooting guide and see, how it goes. Thank you!

    BTW...this is how I see this forum, weird duplicated posts...

  • Hello Andrej,

    Thank you for the update.

    They’re  "duplicated entries" what happens is when somebody marks an answer as suggested, it moves to the Top of the Post. Hence, it’s easier/faster to identify a suggested/valid answer in the post. (Usually, the first Suggested answer will only show until there’s a verified answer (Green) 

    You should see "TOP Replies" on the Top left part. 

    As per your issue, I would recommend you to get a case open with Support for them to investigate along with you, I suspect that the issue might be related to IPsec acceleration (you can try to disable it from the console of the Sophos Firewall via Putty (4) and running 

    console> system ipsec-acceleration disable

    However, this would be only a workaround and not a solution. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi Andrej Pirman

    Make sure Phase I and Phase II are same on both Sophos and other side router as well as try with Remote ID and Local ID settings

    Thanks and Regards

    "Sophos Partner: InfrassistTechnologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Hi  

    For now and with your excellent help, this looks most promissing. Since we did this change, VPN is up and running. I hope it will stay and will certainly report back in a day or two. For now I am monitoring connection. Thank you a lot!

    console> system ipsec-acceleration disable

  • Hi  , I am also with Sophos. I was just curious, what SFOS release do you have running on the XGS-126?

  • Hi,

    at the moment it is still SFOS 19.0.1 MR-1-Build365 firmware.

    So far we figured out, that VPN drop outs were caused by Draytek, which was VPN server for one Sophos device and another Draytek device. After VPN dropout, that other Draytek did call back and re-initiated VPN tunnel UP very soon, but Sophos somehow did not. 

    As a workaround we reversed the VPN tunnel direction, so that Draytek is calling Sophos, meaning after each dropout Draytek re-initiates connection to Sophos and connectivity is restored.

    But it means we only masked out the problem.

  • PROBABLY SOLVED!

    With extensive help from  (thank you very much!) we came to conclusion, that VPN tunnel between Sophos and Draytek is only problematic, when Sophos is initiating connection to Draytek. So we reversed the direction of VPN tunnel, but still there were problems with dropouts. Indded tunnel dropped down every 30 minutes or so, but if Draytek was initiator, it came back every time. It was a workaround.

    Then I investigated Draytek Firmware and found out, that just recently Draytek found some IPSec Phase 1 and 2 incosistencies and they published new Firmware. With this new firmware on Draytek, VPN tunnel did not drop down anymore, and after either side rebooting or loosing connectivity, it re-initiated successfuly. 

    I suspect Draytek had an issue with dropping VPN tunnel in such a way, that only another Draytek was able to re-initiate, but Sophos did not. But as told, after Draytek firmware update, this seems is not an issue anymore.

  • Hi, wich settings do you have on the Draytek? i have the same Issue and Updatet the Draytek but its not working.

  • Hi,

    I have these settings in DRAYTEK, see below.

    But connection between SOPHOS and DRAYTEK is still dropping every few hours, while DRAYTEK-to-DRAYTEK is up for more than 400 hours now. On all sites. But despite of falling down, now SOPHOS at least reconnects back automatically, which it was not the case before DRAYTEK update (it dropped and never came back).

    SITE 1, top one is DRAYTEK-to-DRAYTEK, 2nd one is DRYTEK-to-SOPHOS (dropping at least once per day)

    SITE 1, same situation. See, uptime is not the same for DRAYTEK-to-SOPHOS, which means, this has nothing to do with possible internet issues. Also, according to PING graphs, only VPN drops, while internet is up all the time on all sides.

    This is IPSec VPN on one of DRAYTEKS, connecting to SOPHOS: