Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

XG125 with 20 MR2 blocks UDP 500/4500 after upgrade from MR1

Hello,

i need some help.

I have a Branch Office wiht a XG125 and SFOS 20 MR1 up and running.
Laptop connects over a APX320 AP and get a WiFi IP Address.

Laptop was able to connect through Microsoft Always ON VPN (IKEv2) with UDP 500/4500 find to the Head Office Always ON VPN Server.

After upgrading to SFOS 20 MR2, VPN is broken and Laptop claims, that UDP 500/4500 is blocked by the firewall.

If i move the laptop to my home office, all is fine and nothing is blocked.

Is there any change in MR2, that blocks VPN?

I already disabled some rule in device console with

set ips ac_atr exception fwrules 5,6

I already regreated a new WLAN, with the same problem.

I checked for dropped packages (Sophos Firewall: Monitor dropped packets using CLI).

Any idea?

Thanks



Added TAGs
[edited by: Erick Jan at 2:12 PM (GMT -7) on 5 Sep 2024]
Parents Reply
  • Hi Dirk,

    i have a XG115w with SFOS 20 MR2 with the same Wifi Setup and Firewall Rules.
    The XG115w works fine.

    APX is controlled by XG125
    APX is Seperate Zone (Wifi)

    I capture a Laptop in my home Office and i have a capture filter in wireshark, i can see that the client is talking over 500/4500 with the VPN Server.

    But at the XG125 with APX as a WiFi AP, the client doesn´t get any response from the VPN Server. Wireshark show only the traffic from the client laptop, but no response from the APX 320 traffic.

    The client have normal internet (most of the time), but the don´t have VPN (500/4500), XG125 drops all traffic to the client.

    Sri has done the capture and saw the same problem, but has no idea.

Children
No Data