This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAN Interface failure only when using multiple IPs

I am running version 9.405-5 of the Sophos UTM, home license

I have a single WAN port, an internal LAN, and a DMZ.  These are each physically separate.

I have two masquerading rules:

     Internal LAN (Network) -> External (WAN)

     DMZ (Network) -> External (WAN) (Static)   Note: due to the problem described below this has been changed to External (WAN)

I have two IP's assigned to the External (WAN) interface:

     The first IP is a dynamic IP received from the ISP

     The second IP is a static IP assigned by the ISP

     There is a virtual MAC address assigned to the interface (old equipment was replaced and it was easier than changing the MAC with the ISP)

I have multiple servers with DNS entries to that static IP.

Problem: I updated to the newest version of the UTM. For three days I have been getting intermittent connection problems, failing more often than not.  A ping to the static IP shows 345 total packets, 203 of which were dropped. (that is 58% loss). Ping to the dynamic IP show a similar result. The ISP confirms that connection is stable to the modem, and the problem is with the firewall. I then disabled the additional static IP and pings are near 100% success to the dynamic IP. Multiple reboots of the UTM show the same thing, the interface works perfectly when only using the dynamic IP, but starts showing failures and packet drops when both are used.

I have not assigned the static to the interface to replace the dynamic since this is not the desired setup.

 

Are there any ideas on what I may have done wrong?



This thread was automatically locked due to age.
Parents
  • Just a guess: you Up2Dated to 9.405 and you're having problems because your ISP assigned an incorrect MTU.  Google site:community.sophos.com "9.405" MTU to find workarounds.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • BAlfson said:
    Just a guess: you Up2Dated to 9.405 and you're having problems because your ISP assigned an incorrect MTU.  Google site:community.sophos.com "9.405" MTU to find workarounds.

    My MTU is set to 1500, and is not being reset to 576 or any other MTU.  The system works great under just the dynamic, however I have to change the DNS records on my ISP's site every time things change, this is not ideal or even remotely acceptable. However it is a good workaround until I can find the problem.

Reply
  • BAlfson said:
    Just a guess: you Up2Dated to 9.405 and you're having problems because your ISP assigned an incorrect MTU.  Google site:community.sophos.com "9.405" MTU to find workarounds.

    My MTU is set to 1500, and is not being reset to 576 or any other MTU.  The system works great under just the dynamic, however I have to change the DNS records on my ISP's site every time things change, this is not ideal or even remotely acceptable. However it is a good workaround until I can find the problem.

Children
No Data