Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

kein IPsec VPN nach Upgrade auf SFOS 20.0.1 MR-1-Build342

Hello,

all our Site-to-Site-VPN don't work again after upgrading from SFOS 20.0.0 GA-Build222 to SFOS 20.0.1 MR-1-Build342.

In the log we find: 

(unnamed) - Couldn't parse IKE message from ..

Also all outgoing remote IPSec don't work again after upgrading:

Child SA (Security Association) konnte nicht hergestellt werden.

Can anyone help?

Thanks

Uwe



Add V20.0 MR1
[edited by: Erick Jan at 1:51 PM (GMT -7) on 1 Jul 2024]
Parents
  • Hello,
    we have the same error. However, after updating to SFOS 20.0.1 MR-1-Build342, we rolled back to SFOS 20.0.0 GA-Build222. Since then, the IPsec connections with Sophos Connect no longer work. These worked perfectly before. 

    Error message: Child SA (Security Association) konnte nicht hergestellt werden.
    Couldn't parse IKE message from .. Is there already a solution or a HowTo for this?

    Thanks

    Sebastian

Reply
  • Hello,
    we have the same error. However, after updating to SFOS 20.0.1 MR-1-Build342, we rolled back to SFOS 20.0.0 GA-Build222. Since then, the IPsec connections with Sophos Connect no longer work. These worked perfectly before. 

    Error message: Child SA (Security Association) konnte nicht hergestellt werden.
    Couldn't parse IKE message from .. Is there already a solution or a HowTo for this?

    Thanks

    Sebastian

Children