Hello,
I have an issue with site to site vpn IPSec. I suppose it is a bug.
Scenario:
You have 1 WAN port (port 2)
You have some created site to site VPN IPSEC (initiate the connection type)
Follow these steps to reproduce the issue:
- Configure a new WAN interface (in my case port 10)
- Disable previous WAN port (port 2)
- Change the VPN settings (listening interface to port 10 and local id, with new ip address)
- Save
You will not able to start the connection, an error will appear: "The connection's local interface is turned off. You can't activate or establish this connection.". So, the firewall continues to use port 2 instead of port 10.
To fix the issue, I simply needed to recreate the VPN profiles using the same settings of non-working profiles. This issue happened for my 2 VPN. So, you cannot change the wan port used, after the creation of VPN profile.
F.
Hi eclipse79 ,
Thank you for reaching out to the community, can you please share the logs (strongswan.log) and the current active firmware ?
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello there,
What Firmware version are you using?
Regards,
Thank you for the update, suspecting - NC-135467, Request you to log a service request, so that we can help validate and expedite the investigation. Will be addressed in v20.0.2 MR2
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
hello, I have read the page you linked. I used service strongswan:debug -ds nosync syntax and show again strongswan.log file... but I continue to see no entries related to the VPN name I started
We are experiencing the same issue. I don't have time to waste hours with support to capture logs. Going to re-create the VPN as suggested.
eclipse79 , we are tracking this issue issue internally, will get back on the release it will be fixed.
Hi eclipse79 and NexusHelp Sophos Firewall OS v20 MR2 is Now Available and contain the fix for this issue.
community.sophos.com/.../sophos-firewall-os-v20-mr2-is-now-available
Regards,
Vishal Ranpariya
Technical Account Manager | Sophos Technical Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'Verify Answer' link.