This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Broken IPsec tunnels

Hello Community,

Am I the only one or does this sound familiar? If it does, does anyone have suggestions on how to deal with it.

We make use of a number of hosts and networks in AWS. We connect to them using IPsec tunnels. Setting these up with the UTM is simple enough. But, sometimes a tunnel goes down. I haven't been able to find the cause. And since these tunnels are set up redundant (in our case double redundant) in most cases I don't even notice. But if I do notice, every time it seems to help to manually disconnect and connect again. This works, only because I have these double redundant tunnels because disabling will stop both tunnels of a connection (connection meaning the redundant tunnel from one of my outbound connections).

The best solution would obviously be that Sophos retries broken connections more often (Sophos seems to retry because if I do nothing, problems also go away, but only after a long time). It would also help if you could retry a single broken tunnel from the GUI.

But since it will be a while before Sophos follows up on this, it would be great if someone could tell me how I can force a reconnect for a single tunnel. I would like to create a script that checks for broken connections and retries them. And reports by e-mail. But is it even possible?

Thanks for all suggestions  (or moral support), Jan



This thread was automatically locked due to age.
Parents
  • Hoi Jan,

    What do you see when you execute the following command as root?

    cc get_objects amazon_vpc tunnel

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • A list with a lot of tunnels :-)

    Incidentally I had the issue again half an hour ago. But this time after disabling the connection where one of the two tunnels was down, it failed to enable again. And every time I try to enable the tunnel, it has impact on other connections as well. I see the uptime counters often jump back to zero and also other tunnels went down. Most of the them came back up again, but it all feels very shaky.

  • What does Sophos Support have to say about this, Jan?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data