I've been experiencing intermittent issues with our ISP going down the past month. They've all occurred after hours/overnight, so I believe they were actually making repairs due to damage sustained from a partial building collapse a block away. The connection seems back to normal as of this weekend speed and stability wise. The problem is when the drops have occurred, my VoIP phones are losing connection to our SIP provider, when the WAN comes back up, the phones attempt to use the old ports and are not able to regain service. I have to clear the nat table with conntrack -F then restart the phones to get them to regain service. Is there a way to clear the nat table for my phone vlan upon wan timeout so that the phones can gracefully recover when the wan comes back up?
I've read the following discussion, but it does not appear a fix was found and I also do not have a backup WAN.
clearing NAT for voip sip after dual wan failover - Discussions - Sophos Firewall - Sophos Community
Hello Jeff,
Good day and thanks for reaching out to Sophos Community.
It seems this is similar and related to NC-118215/NC-116890 where it has been fixed on MR3 https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=xg&versionID=19.5
Could you try to update your SF to MR3 and let us know if it fixes the issue.
Many thanks for your time and patience and thank you for choosing Sophos.
Cheers,
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Raphael, coincidentally I updated to MR3 build 652 on last Thursday 8/17 and was still experiencing issues with the reconnecting of the phones as recently as Monday morning from an outage Friday night. However, on last Tuesday 8/15 I had moved the phones to a separate VLAN that got its dhcp addressing and options directly from the XGS. I discovered that the firewall was not properly passing option 66 to the devices even though it was configured. Link below that option 66 actually sends the firewall IP instead of what is configured in the option. I decided to relay the VLAN to get DHCP from my windows DHCP servers due to the issues on Monday evening and realize now that an outage that occurred just after submitting my discussion resulted in the phones gracefully recovering. I will monitor for a few more days, but am hopeful that the ISPs visit today resolved what was causing our outages.
PXE Boot DHCP Option 66 + 67 - Client falsely using the Firewall IP-Address as TFTP Server
Hi Jeff,
Thanks for taking the time to update and glad your phones comes to graceful recovering after a disconnection from ISP, yes please continue to monitor and feel free to share any update you might have on this thread.
Many thanks for your time and patience and thank you for choosing Sophos
Cheers,
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids