- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSEC / Site-to-Site VPN problem with Sophos XGS
Hey all,
I have a strange IPSEC/ Site-to-Site VPN issue.
Initial a VPN tunnel works from Meraki MX to Sophos XGS.
After Phase 1 lifetime is reached, only one SA is alive, others are gone.
Restarting the tunnel helps until lifetimes ends.
The tunnel is not getting ready/active when new traffic is generated.
Please do not wonder why my lifetimes are that low. I had issues with tunnel with 28800 seconds. Troubleshooting was really time consuming, so I changed multiple times to lower values.
I have other tunnels to Azure with multiple networks, and this tunnel(s) are working.
Azure <-> Meraki
Azure <-> Sophos XGS
Meraki <-> Sophos XGS (not working)
EDIT: I was using IKEv2....
To avoid conflicts I have also created fake VLANs on my Meraki site.
First screenshot. After enabling the tunnel
Second screenshot: After 10 minutes when Phase 1 has ended
Sophos IKEv2 settings
Meraki IKEv2 settings
Solved! Go to solution.
- Labels:
-
3rd Party VPN
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
>After Phase 1 lifetime is reached, only one SA is alive, others are gone.
On Meraki you can only have one IKEv2 SA subnet pair active at a time. IKEv1 does not have this restriction. You'll need to change to IKEv1.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi ,
What MX firmware are you using ? I found that MX 19.1.X fixed a lot of our NMVPN issues.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A wild mix of MX 18.211.4, MX 18.211.5, MX 18.211.2
With all of them I had problems. I have seen that you have really many devices in another thread. How is 19.1.X ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunatly I don't have many sites with NMVPN , so only a few were upgraded to MX 19.X . All my other devices are also running a mix of MX 18.
But so far so good with MX 19.X. That might be worth trying on a site / lab on your end if possible.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am currently preparing a lab environment. Still waiting for new hardware. I give it a try and maybe S2S is stable with this firmware.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
>After Phase 1 lifetime is reached, only one SA is alive, others are gone.
On Meraki you can only have one IKEv2 SA subnet pair active at a time. IKEv1 does not have this restriction. You'll need to change to IKEv1.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What @PhilipDAth said is the answer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are killing me.... it works with IKEv1 instantly.... I am now waiting until lifetime ends the second time.
Edit: It works now for the fourth time. Thanks a lot for the information, hopefully the team may change it in future to work the same way with IKEv2 . 🙂
