Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

XG125 with 20 MR2 blocks UDP 500/4500 after upgrade from MR1

Hello,

i need some help.

I have a Branch Office wiht a XG125 and SFOS 20 MR1 up and running.
Laptop connects over a APX320 AP and get a WiFi IP Address.

Laptop was able to connect through Microsoft Always ON VPN (IKEv2) with UDP 500/4500 find to the Head Office Always ON VPN Server.

After upgrading to SFOS 20 MR2, VPN is broken and Laptop claims, that UDP 500/4500 is blocked by the firewall.

If i move the laptop to my home office, all is fine and nothing is blocked.

Is there any change in MR2, that blocks VPN?

I already disabled some rule in device console with

set ips ac_atr exception fwrules 5,6

I already regreated a new WLAN, with the same problem.

I checked for dropped packages (Sophos Firewall: Monitor dropped packets using CLI).

Any idea?

Thanks



Added TAGs
[edited by: Erick Jan at 2:12 PM (GMT -7) on 5 Sep 2024]
Parents Reply
  • Why does the  XG125 get´s this log entries in IPSec (charon.log)?
    There are a mass of entries.

    2024-09-09 10:35:56
    VPNmessageid="18050" log_type="Event" log_component="IPSec" log_subtype="System" status="Deny" user=""
    con_name="" con_type="0" src_ip="" gw_ip="" local_network="" dst_ip="" remote_network=""
    additional_information="" message="Received IKE message with invalid SPI (9FC31E20) from the remote gateway."

Children