This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec VPN keeps down after DSL lines reconnects...

i run several ipsec tunnel for years without any problems... all runs fine with 9.355-1


since the update to 9.402-7 all ipsec tunnels are down every morning.


i checked the ipsec-logs and found out that after my dsl-lines reconnect the tunnels will not come up again.

i have to turn them off and on and then all works....


anyone can help?



This thread was automatically locked due to age.
  • Hi Sachin,

    we have posted some logs and more and more users report the same problem.

    Seems to be a firmware-bug isnt it? will it be fixed and when?

    Can we get a hotfix from support for this or will it be in next GA-Update?

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • From Sophos I get this Number for the problem NUTM-4173 

  • Hi All,

    This is bug NUTM-4173. A fix will be provided in next firmware release.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • I spend several hours to the same problem too, same problem here

    Site 1: UTM/ASG 220 Appliance 9.403-4

    Site 2: UTM/ASG 120 Appliance 9.403-4

    Site-to-Site IPSec works with 9.355-1 and is broken every morning after DSL reconnect since update to 9.403-4

    VPN User can´t log in at this time. Only after reboot.

    My way to bring back the tunnel: restart UTM every day at 2...

    does not test sophos its firmware?

    we are endtesters? we are working with productive systems.....this is not possible!!

    When will be fixed this? Time is running :-(

    Greetings

    Dirk

  • Hi Dirk,

    I stay on my rollback to 9.355, until sophos fixes the NUTM-4173.

    If you have

    - Site 1: more DSL Interfaces (Gateway type: initiate connection)

    - Site 2: only one DSL Interface (Gateway type: answer mode)

    you could try to change the direction of the tunnel initiation

    - Site 1: answer mode

    - Site 2: initiate connection

    I do no more tests since I spent to much time with this problem ...

  • When will Sophos release a fix? We are waiting!

    Restarting VPN every night is way beyond annoying. [:@]

  • agree !!

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Today my boss was earlier at work at 6:00 and wanted to work, but he couldn't because there was no working VPN to our HQ. Now he is VERY upset about the whole situation. Unfortunately we were just about to buy a new hardware appliance with TotalProtect for three years, and now he thinks to "throw this Sophos sh*t out!" [:(]

    Can we please get some feedback from Sophos here? When will you release the fix?

  • I have this Problem for more than a year now with all versions up to 9.402 ...

    The only workaround was a cron job that restarted the UTM every night after the VDSL reconnects.

    But even then, after some weeks it only helps to turn power off and on again ...

    It happens on multiple SG125  as well as on a software version runing as a VM ...

    Until now it was sporadically every 2-3 Weeks, now it's every day after pppoe reconnects. ( German Telekom VDSL )
    Suphos support ignored my requests for month ! 

    I think these support guys should talk directly to our bosses , mine are also "not amused" when they cannot work from remote.

    I also did throw out the money for the SG's

    In my case it's people in 2 Offices cannot work !!!

    It is absoutely annoying that vital, basic things like these take month to be seen and fixed ...

  • Unknown said:

    I have this Problems for more than a year now with all versions up to 9.402 ...

    The only workaround was a cron job that restarted the UTM every night after the VDSL reconnects.

    But even then, after some weeks it only helps to turn power off and on again ...

    It happens on multiple SG125  as well as on a software version runing as a VM ...

    Until now it was sporadically every 2-3 Weeks, now it's every day after pppoe reconnects. ( German Telekom VDSL )
    Suphos support ignored my requests for month ! 

    I think these support guys should talk directly to our bosses , mine are also "not amused" when they cannot work from remote.

    I also did throw out the money for the SG's

    In my case it's 2 complete Offices that cannot work !!!

    It is absoutely annoying that vital, basic things like these take month to be seen and fixed ...