Non-TCP connections get disconnected whenever an IPsec tunnel comes up/down (UDP, VoIP)
Zitat von mpachmann am 3. April 2025, 10:01 Uhrhttps://support.sophos.com/support/s/article/KBA-000008802?language=en_US
Issue
Non-TCP connections get disconnected whenever an IPsec tunnel, either site-to-site or remote access VPN, comes up/down. This affects RDP, VoIP, and other non-TCP connections.
Product and Environment
Sophos Firewall - All supported versions
Symptom
- RDP in other Sophos Connect users experience a re-connect whenever a Sophos Connect user signs out.
- VoIP phones get disconnected.
- SSL VPN is disrupted.
Cause
All non-TCP connections on the VPN and WAN zones are deleted by design during an IPsec tunnel up/down event. This will cause existing non-TCP connections to be disconnected.
Resolution
As a workaround, do any of the following to make non-TCP applications or connections stable:
- Make sure all applications running over IPsec VPN connections are TCP only.
- Turn off the default disconnection behavior on Sophos Firewall:
- Access your Sophos Firewall console.
- Select Device Console and run the following command:
set vpn conn-remove-tunnel-up disable
Sign up for the Sophos Support Notification Service to receive proactive SMS alerts for Sophos products and Sophos Central services.
https://support.sophos.com/support/s/article/KBA-000008802?language=en_US
Issue
Non-TCP connections get disconnected whenever an IPsec tunnel, either site-to-site or remote access VPN, comes up/down. This affects RDP, VoIP, and other non-TCP connections.
Product and Environment
Sophos Firewall - All supported versions
Symptom
- RDP in other Sophos Connect users experience a re-connect whenever a Sophos Connect user signs out.
- VoIP phones get disconnected.
- SSL VPN is disrupted.
Cause
All non-TCP connections on the VPN and WAN zones are deleted by design during an IPsec tunnel up/down event. This will cause existing non-TCP connections to be disconnected.
Resolution
As a workaround, do any of the following to make non-TCP applications or connections stable:
- Make sure all applications running over IPsec VPN connections are TCP only.
- Turn off the default disconnection behavior on Sophos Firewall:
- Access your Sophos Firewall console.
- Select Device Console and run the following command:
set vpn conn-remove-tunnel-up disable
Sign up for the Sophos Support Notification Service to receive proactive SMS alerts for Sophos products and Sophos Central services.