This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unstable Connection on all RED 15w till restart of UTM 9

Greetings,

we have set up two SG 135 (one as Backup-Slave) in our head office and five RED 15w in different locations. To the main SG 135 three interfaces are connected: VDSL (main connection via PPPoE), SDSL (as WAN-Backup) and ADSL (also via PPPoE but not used since the first test runs showed that the RED 15w devices had problems to connect over the ADSL interface - constant reconnects every minute).

 

The network setup is nothing special. Till now only one Internal Zone which connects everybody. First i tested the setup with only two RED 15w set up and the two SG 135. It worked over a month without a problem. So i joined the left over RED 15w.

 

The problem is now that between 8:30 AM and 8:50 AM the State and Link of all five RED 15w Boxes goes up a and down rapidly. Till i restart both of the SG 135. After that the network functions without a problem... till the next day between the timespan 8:30 AM - 8:50 AM. A simple reconnect of the VDSL Interface doesnt help. I need to fully restart both of the SG 135 (a reconnect via the interface works fine). If i restart both SG 135 before the timespan (for example at 7:50 AM) the system works fine without any problems around 8:30 AM.

 

I dont have a clue what is the origin of this behaviour and of course i want to find a solution to this problem. Is maybe the unused (but connected) ADSL Interface or the SDSL WAN-Backup the problem? Should i fully disconnect them at all ?

 

Also i am not shure if our HA Cluster is configured correctly since i have to restart both SG 135 manually (Connect to Sophos Web Interface -> Restart -> Refresh page to get access to the second SG 135 which shows like all Interfaces as down -> also Restart -> Both SG 135 get up again and everything works as intended). The Operation Mode is set to Hot Standby with no preferred master and the interal interface selected as Backup interface (an external service provider set the two SG 135 up for us).

 

I hope you can help me out since i dont want to restart the system every morning.

 

Thanks!



This thread was automatically locked due to age.
Parents
  • Hi, Marcel, and welcome to the UTM Community!

    Go ahead and get a ticket started with Sophos Support first.  Please insert the portion of the RED log where things go awry.  Also, anything that seems related in the System messages and Fallback messages logs.

    Does the ISP reset these connections at that time?  Perhaps you could have them do the reset at 2AM and then, as a workaround, add a cronjob reboot just after that.  Do you have a daily reconnect configured for the PPPoE Interface?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Marcel, and welcome to the UTM Community!

    Go ahead and get a ticket started with Sophos Support first.  Please insert the portion of the RED log where things go awry.  Also, anything that seems related in the System messages and Fallback messages logs.

    Does the ISP reset these connections at that time?  Perhaps you could have them do the reset at 2AM and then, as a workaround, add a cronjob reboot just after that.  Do you have a daily reconnect configured for the PPPoE Interface?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Hi Bob,

     

    My ISP should'n reset the connection at any time. But maybe i should call them again. On my search for a solution i already tried to configure a daily reconnect. Did not help and like said, should not be needed.

     

    A daily restart of both SG 135 via a cronjob sounds like an easy fix but somehow feels sloppy?

     

    I will get a ticket out to the Sophos Support. I hope i can get help there.

     

    Greetings

  • You might try posting the logs here that I mentioned if Support hasn't already resolved your issue.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA