Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XFRM showing 'not configured' after public IP changes on spoke

Hello,

we are currently using Sophos Firewalls in a Hub-and-Spoke topology running SFOS 20.0. Some spokes are using WAN connections with dynamic IPs which will change from time to time.

On those units we can observe that the corresponding XFRM interface on the hub won't come up from time to time after the spoke changes its IP-address. DPD seems to be working just fine and the tunnel itself will reconnect after the ISP assigned the new IP to the spoke. However the XFRM will not come back to the 'Connected' state. To resolve this issue, we have to manually disable and re-enable the tunnel.

This is catastrophic since the spokes are using the hub as exit node in this topology.

The issue seems to be documented here already:

 XFRM issue after provider IP-change 

Are there any known fixes or workarounds for this issue? Would upgrading to 20 MR1 resolve the issue?



This thread was automatically locked due to age.