This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cisco VPN Client not route after update 9.409-9

Hi,

i have updated my Sophos UTM SG310 to the version in subject.

Before i did the update I could get access on every network devices over Ipesc Cisco with the iPhone of my company.

Now after the update I'm not able to do it anymore.

The Connecting and the authentication are ok (VPN Connected) but I can't ping any device on any network (Request timeout).

SSL and PPTP works fine.

 

Can somebody help me about this issue ?

 

Tommaso

 



This thread was automatically locked due to age.
  • Hi,

    if you are using CISCO VPN on your iPhone there is a problem according to SHA2 truncation. CISCO VPN needs non-RFC truncation after 96 bit. RFC-standard is 128 bit.

     

    To change the policy for CISCO VPN back to 96bit truncation, please execute the following command line

            cc change_object REF_IPsecPolicyCisco ipsec_auth_alg sha2_256_96

     

    Please report if this solves your problem. At least for iOS there are several other customer where this was the solution.

    Thank you in advance

    Regards,
    Holger

  • Hello Holger,

    This solves my problem!

    Thank You!!!

    BR,
    Michael