This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT Traffic (UDP 500/4500) - connection is disturbed and breaks frequently

Hello,

we use Microsoft Always On for all Home Office Users.

The clients connect to a public IP of our XGS2100.

The Firewall uses a symetric Fibre connection (100MBit) from German Telekom.

XGS has NAT and forwarding rule to the internal RAS/VPN Server for UDP 500/4500.

SSL/TLS is currently disabled, IPS is disabled for this firewall rule at console level.
I tried some QoS Rules, no luck.

In the last days, we had massiv problems with the connection (started after migration to 19.5.1 a few weeks ago).

Is there anything else i could verify/change at Firewall (XGS 19.5.1)?
I have a ticket with sophos and the Technical Support Engineer couldn´t find any problem within the firewall.

He checked the rules, did some tracedumps at cli, check drops, etc...

As a workaround i switched the Public IP and the RAS/VPN Server to a pfsense firewall.


Thanks

Jürgen



This thread was automatically locked due to age.
Parents Reply
  • Hi,

    today i create a ref. setup with sophos firewall and a new RAS/VPN Server (3, Win 2022) .

    The old solution was not working properly if going through Sophos Firewall.
    This was tested with a RAS/VPN Server (1, Win 2019) and RAS/VPN Server (2, Win 2022).

    With RAS/VPN Server (2, Win 2022) going through pfsense all seems fine right now.

    I will get a setup with a new RAS/VPN Server (3, Win 2022) going through Sophos.
    So the old RAS/VPN Server (1, Win 2019) will not be involed at all.

    I will test today with a remote client.

Children
No Data