Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Firewalls do not connect backup to the internet after ISP goes down and back up

I have two clients that use the same ISP. One client has an XGS87 and the other XGS116. The ISP does scheduled maintenance at night knocking the firewall offline. My clients will have to power cycle the firewalls to get them to connect in the morning after this. One client has a static IP assigned, IPv4 the other client is set to DHCP. 

I also have a third client with an XGS116 on a different ISP and this happens as well. I have never had this issue with other firewalls I have used in the past. My clients are becoming frustrated. Is there anything I can do or try?



Added FR TAG
[edited by: Erick Jan at 12:04 AM (GMT -8) on 11 Nov 2024]
Parents
  • Hello  ,

    I am not sure whether below mentioned feature request (SFSW-I-1139) would help here.

    As per your report, you have one appliance with "static" WAN interface as well which is also facing issue, right?

    To understand your problem in better way, could you please help resolving these queries?

    - After ISP scheduled maintenance is over, is client able to ping firewall from LAN side?

    - If yes, from firewall, did you check whether gateway IP is reachable via ping?

    - What's ARP resolution state of the gateway?

    - Which firewall version you are using?

    - Did you observe this issue before?

    - How is ISP connected to Firewall WAN? Is it via some L2/L3 switch or some other means?

    - It's possible that ISP is not in consistent state after maintenance activity and upon power cycle of Firewall, link up/down or ARP query might be restoring ISP's state into working mode?

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

Reply
  • Hello  ,

    I am not sure whether below mentioned feature request (SFSW-I-1139) would help here.

    As per your report, you have one appliance with "static" WAN interface as well which is also facing issue, right?

    To understand your problem in better way, could you please help resolving these queries?

    - After ISP scheduled maintenance is over, is client able to ping firewall from LAN side?

    - If yes, from firewall, did you check whether gateway IP is reachable via ping?

    - What's ARP resolution state of the gateway?

    - Which firewall version you are using?

    - Did you observe this issue before?

    - How is ISP connected to Firewall WAN? Is it via some L2/L3 switch or some other means?

    - It's possible that ISP is not in consistent state after maintenance activity and upon power cycle of Firewall, link up/down or ARP query might be restoring ISP's state into working mode?

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

Children
No Data