Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cellular WAN constantly showing up and down, but never *actually* going down

Brief description of my setup:

WAN1 is a hardline connection.

WAN2 is a cellular 5G connection, using a standalone antenna and modem.

SD-WAN 1 is configured for general internet traffic, where WAN1 is the default and WAN2 is failover, using TCP connection to 8.8.8.8 and 9.9.9.9 on port 53 for connection health checks.

SD-WAN 2 is configured for VoIP traffic, and configured as load balancing, selecting the best connection at any given time, using TCP packets to 8.8.8.8 on port 53, and 54.172.60.0 (twilio server) on port 5060 (SIP) for health checks eligibility.

The problem I'm having is that I am very frequently, 10-20 times a day, getting notifications that my Cellular WAN is down, then moments later, back up. However, the cellular WAN never actually goes *down.*

The alert email looks like "*ALERT* Sophos Firewall "X111039#######" - Gateway 'T-mobile WAN' is Down." I have worked with the antenna maker (cradlepoint) to try to diagnose any issues there, but we were unable to find any issues. There is no noted downtime on any of the antenna's hardware logs. He did note that sometimes cell providers will block ICMP traffic, which is why i switched my SD-WAN health checks to TCP, but the issue still persists.

Lastly, I am wondering if it is possible to change the Gateway's health check protocol (i believe the default is an ICMP ping)? If the gateway is part of a SD-WAN profile, are there still Gateway health checks being performed?



This thread was automatically locked due to age.
Parents
  • Hi,

    the issue will more than likely be the device you are using as your network test in WAN manager is being overloaded and fails to respond to  pings. Please try using a different IP address as your test.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • It only fails on the one gateway. If the problem were with the test endpoint, I would more than likely see intermittent failures on on both WAN links, moreover, i have switched up my health checks - from basic ICMP pinging, to TCP DNS requests, to hitting my VoIP provider at the SIP port. All of these health checks work fine from the device console, some are just more reliable than others.


    XGS116 20MR2

  • "*ALERT* Sophos Firewall "X111039#######" - Gateway 'T-mobile WAN' is Down."

    This alert is given by default when the "WAN Link Manager" fails to ping the upstream gateway. (Not related to SD-WAN.)

    Can you please go to "Network" then open the "WAN Link Manager" tab and edit the WAN2 gateway to another host.

    To add more information, I've encountered this same issue a while ago - mainly on peak load times of the ISP.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

Reply
  • "*ALERT* Sophos Firewall "X111039#######" - Gateway 'T-mobile WAN' is Down."

    This alert is given by default when the "WAN Link Manager" fails to ping the upstream gateway. (Not related to SD-WAN.)

    Can you please go to "Network" then open the "WAN Link Manager" tab and edit the WAN2 gateway to another host.

    To add more information, I've encountered this same issue a while ago - mainly on peak load times of the ISP.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

Children
  • So WAN2 is configured as DHCP - it is statically assigned by the ISP and never changes, so the gateway spec is coming from them, not me. What you say though, "fails to ping the upstream gateway" - what if the ISP denies this traffic? I've seen the Cellular ISP just drop ICMP packets. Can a different method of gateway health check be configured?


    XGS116 20MR2

  • So WAN2 is configured as DHCP - it is statically assigned by the ISP and never changes, so the gateway spec is coming from them, not me.

    There's no need to edit the assigned DHCP address, the gateway monitoring is another service - ("kinda" not related to the interfaces page.)

    what if the ISP denies this traffic? I've seen the Cellular ISP just drop ICMP packets. Can a different method of gateway health check be configured?

    Yes, you can change the gateway health check method to TCP + Port, you can find more information here: Edit gateway details - Sophos Firewall and here: WAN link manager - Sophos Firewall.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • First go to "Network", then "WAN Link Manager" and edit the WAN2 (T-Mobile) Gateway.

    After It press "Edit"

    Then change to the desired TCP + Port + IP Address,

    I recommend you to change to -> 1.1.1.1 Port 53.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • haha! I can't tell you how many times i looked at that and didn't click edit. ui/ux failure. oh well. that is what i was looking for, Thanks!


    XGS116 20MR2