Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

TCP Disconnect with IPS-Pattern updates ??

We have some customers who use quite sensitive software.
We have had repeated session drops with one customer (always at noon on Tuesdays -GMT-)
The IPS patterns are said to have been updated at this time today.
IPS is only active for some external connections. Not for the "sensitive" internal ones.
They are running version 20.0.1 MR1
Could there be a connection?

Thanks Dirk



Added TAGs
[edited by: Raphael Alganes at 1:14 PM (GMT -7) on 25 Jun 2024]
Parents Reply
  • Since this happens once a week (so far), it is not easy to capture the correct traffic.
    The only thing we see... the moment of disconnection (multiple devices losing connection to servers and devices at the same time) matches the time of an IPS pattern update (Timestamp of Last successful update of IPS and Application signatures)

    From SG we know the "Restart policy - Bypass IPS scan".
    Maybe there is something similar at XGS?
    But I have a lot of customers using this software and IPS for external connections and never I saw such problems before 20.0.MR1


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children