This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems with HA in latests firmware versions ( 17.02)

We are experiencing a lot of problems with HA with Sophos XG 210 and 230 Models in firmware 17.02

They are configured as Active / Passive as in firmware 16

Disconnecting the LAN cable from the Active Appliance, the Passive has started but there wasn't any internet connection. This should be worked as older firmwares (16 and older). But the worst issue was that when connected the LAN cable on the first Firewall, There was no IP response on the LAN Port. 

we've shut down all firewalls and switches and started again connecting only a laptop to the Firewall and no response of the LAN port, but if I try to connect to the WAN port, It works and I can manage it... Why??? 

 

 

We have disconnected, unracked and move it to the lab and still doesn't works. Suddenly after a lot of minutes without doing anything, the LAN Port start working. 

 

We have experiencing a lot of weird issues like this with the latest firmware versions. Anyone has found anything similar??

We have 3 Pair of HA XG (Active-Passive) distributed on different offices interconnected by VPNs, and we found the same problems in all of them... They are in Production Environments and are very critical, and we are very disgusted with all these troubles and our Customer wants a stable Firewall like Fortinet or other manufacturers.

Hope that Sophos bring us a solution or we will consider starting working with others Firewalls.

Best Regards



This thread was automatically locked due to age.
  • Hi Jordi,

    It can be a tricky question to answer as we have limited sources to check it via the community medium. Please PM me few details and outputs, that would help me investigate this further:

    1. SSH to the XG and go to option 4. Device console and execute, show network interfaces 
    2. Screenshots of the HA configuration on XG.
    3. applog.log, syslog.log, csc.log, capture these logs when you disconnect the LAN interface. Please refer to, Sophos Firewall: Where to find log files.

    Finally, the MTU/MSS and link speed should be default on the dedicated HA port. We recommend connecting dedicated HA link directly to two appliances. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.