Advisory: Sophos Endpoint "Your connection isn't private" after reboot. Policy settings can be returned to normal. See: KB-000045954 for the latest updates.

IPSec Site to Site VPN Disconnection

Hello,

I have setup a site to site IPsec VPN between a Sophos XG (Responder) & a DrayTek (Initiator) router. Everything is working as it should apart from a disconnection every so often. I believe this has something to do with the re-key event that stated in part 3 of below knowledge article.

 Sophos Firewall: Best practice for site-to-site policy-based IPsec VPN 

I have kept the default key life setting on the XG. Phase 1 = 5400 & Phase 2 = 3600 and have copied to the DrayTek's side. On the XG, I have disabled "Re-key Connection" & "Dead Peer Detection". Both XG and DrayTek are using AES256 SHA2256 for Phase 1 and Phase 2.

I have even changed the key life on the DrayTek's side to something different to test. But I'm still getting the same disconnection errors.

Disconnection error "Name-1 - IPSec Connection Name-1 between XXX.XX.XXX.XXX and XXX.XXX.XX.XXX for Child Name-1 terminated. (Remote: XXX.XX.XXX.XXX)"

Message ID = "17802"

Any ideas?

Thank you =)



Added TAGs
[edited by: emmosophos at 7:22 PM (GMT -8) on 30 Nov 2023]
Parents
  •   Please provide the complete configs used on SFOS side on IPsec page and on the ipsec profile, also on the DrayTek side configs. Also provide the /log/charon.log of SFOS; we need to understand who is disconencting the tunnel first. In case, if the disconnect is happening from Dreytek, why it happens etc.. 17802 message id just says the tunnel is disconnected that could happen either the connection is terminated by the Initiator or by the responder.

Reply
  •   Please provide the complete configs used on SFOS side on IPsec page and on the ipsec profile, also on the DrayTek side configs. Also provide the /log/charon.log of SFOS; we need to understand who is disconencting the tunnel first. In case, if the disconnect is happening from Dreytek, why it happens etc.. 17802 message id just says the tunnel is disconnected that could happen either the connection is terminated by the Initiator or by the responder.

Children