site-to-site vpn from Sophos

Reply
L4 Transporter

site-to-site vpn from Sophos

IKE coming from a Sophos device is incorrectly identified as application ciscovpn instead of application ike.

Is this because Sophos uses cisco-ish protocol ? All I see in the logs is udp 500...

I'm happy allowing application ike, our other site-to-site vpn's work fine with it.

I'm not happy however with allowing ciscovpn, since that would open a bunch of other ports as well (source applipedia: tcp/500,2512,4500,10000, udp/500,4500,10000,62514-62524)

Has anyone noticed similar behaviour ? Can I do something about it ?

Tags (1)
L7 Applicator

Re: site-to-site vpn from Sophos

You could write a specific rule just for the Sophos site ip address as a port based rule before the application rule.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
L4 Transporter

Re: site-to-site vpn from Sophos

That's what we did. But still, I would have expected it to work using only application ike...

L7 Applicator

Re: site-to-site vpn from Sophos

This happens sometimes.  Applications are classified based on the actual behavior and content of the packets.  So the connection here was similar enough to the Cisco to make a match.

You could open a support case and provide the pcaps on the misclassification.  Then the application signature might be able to be updated in a future release.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!