This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED Disconnections since Firmware 9.704-2

Hi guys,

i'm having problems with my site2site RED Connections. Firewall Server is a SG310, the client devices are SG125, SG135, SG210, some of them are connected via 2 RED Tunnels, one over a Layer 2 Connection, one via Internet...

If i disable tunnel and re-enable it, the connection starts without any issues, OSPF is calculating routes and everything is nice. Also if i change tunnel compresion on Server Firewall from off to on. A few hours later the connections on the client firewalls start to flap in a time range of ca. 15 - 30 minutes, the restarts take about 8 - 10 seconds, on the redundant connected client firewalls both of the tunnels are affected. Regarding the reconecttion time the site is offline the outage is noticable, since OSPF Routes are recalculated...

The RED log file on the client Firewall shows reloading and after that a change in the config file, although nothing changed...

2020:10:04-07:10:26 client_firewall red_client[4582]: SELF: (Re-)loading client configurations
2020:10:04-07:10:26 client_firewall red_client[4582]: Tunnel 1: client config changed, restarting
2020:10:04-07:10:26 client_firewall red_client[24225]: Tunnel 1: disconnected
2020:10:04-07:10:31 client_firewall red_client[4582]: Tunnel 1: Forking client handler
2020:10:04-07:10:33 client_firewall red_client[31916]: CHILD REDv2 Tunnel 1: performing initial keying.

Others with this problem? I notice the problem since updating to version 9.704



This thread was automatically locked due to age.
Parents
  • Servus Alex,

    I don't know why, but there are configurations where using compression seems to cause issues.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    in this case it isn't. I changed the compression settings with no success, the config reload also happened.

    Yesterday i had a conference call with an german Support Engineer and Infinigate regarding this case. Our symptoms matches with these described in NUTM-12280.

    Regards,

    Alex

  • QA is testing. Next Update is scheduled for Week 46...

  • We have the same issues, with and without compression. Since 9.704 or 9.705-3, can't remember. Fairly recently. Debugging with ISP first, then found the Sophos RED culprit.

  • It's fixed. Got a Pre-RPM installed.

    Kind regards,

    Alex

  • Thanks for this, did you use NUTM-1228 for reference?

    I have the exapt problem with 9.705 and no compression:

    2020:12:07-04:00:24 fw11 red_client[29017]: SELF: (Re-)loading client configurations
    2020:12:07-04:00:24 fw11 red_client[29017]: Tunnel 17: client config changed, restarting
    2020:12:07-04:00:24 fw11 red_client[23533]: Tunnel 17: disconnected
    2020:12:07-04:00:29 fw11 red_client[29017]: Tunnel 17: Forking client handler
    2020:12:07-04:00:32 fw11 red_client[18312]: CHILD Tunnel 17: performing initial keying.
    2020:12:07-04:00:32 fw11 redctl[18317]: key length: 32
    2020:12:07-04:00:32 fw11 redctl[18318]: key length: 32

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Technician

Reply
  • Thanks for this, did you use NUTM-1228 for reference?

    I have the exapt problem with 9.705 and no compression:

    2020:12:07-04:00:24 fw11 red_client[29017]: SELF: (Re-)loading client configurations
    2020:12:07-04:00:24 fw11 red_client[29017]: Tunnel 17: client config changed, restarting
    2020:12:07-04:00:24 fw11 red_client[23533]: Tunnel 17: disconnected
    2020:12:07-04:00:29 fw11 red_client[29017]: Tunnel 17: Forking client handler
    2020:12:07-04:00:32 fw11 red_client[18312]: CHILD Tunnel 17: performing initial keying.
    2020:12:07-04:00:32 fw11 redctl[18317]: key length: 32
    2020:12:07-04:00:32 fw11 redctl[18318]: key length: 32

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Technician

Children