DO NOT INSTALL 9.703-2!!!

DO NOT INSTALL 9.703-2!!!

My lab system was Up2Dated to 9.703-2 Thursday evening at 10PM CDT (UTC -0500) and all connection with the outside world immediately stopped.  My local connection would work normally a few minutes at a time and then everything would lock up for a few minutes.  I could not identify the problem with top, but did see a lot of zombie confd processes.  I lost the entire day of Friday because my wife has a big project due next week and was working via Microsoft Teams all day with her colleagues.

I will suggest to Sophos that the file be removed from the ftp site. Grumble.

Cheers - Bob

  • In reply to jprusch:

    So wait, did Sophos release a new version of this update in the meantime?

    I installed the 9.703-2 update yesterday evening. Haven't had a single problem all day...about 15 people were logged in using SSL VPN, outgoing

    traffic was fine.

    Unsure what to do right now, maybe someone can shed some light?

    We're running UTM Software on a HPE ProLiant server, btw.

  • In reply to Dominik Wagner:

    Hello Dominik,

    we have three sites where this update is running fine, too. I just let them untouched until Sophos has additional infos.

  • In reply to jprusch:

    No, 9.703-2 was the complete number of the intitial release of that update-catastrophe.

  • In reply to jprusch:

    Okay, then I guess I'll do the same and just wait it out...man, a few months ago this disaster with an update shredding RED site to site tunnels...now this SNAFU...somehow one gets the feeling there isn't alot of love left over at Sophos for their venerable UTM product...

    Schöne Grüße ebenfalls aus Deutschland :-)

  • In reply to Dominik Wagner:

    they want to push the XG so UTM isnt the focus. i miss the good old ASG times when you can call a astaro developer directly when you find a bug  in fw, mostly 1 hour later you got a fix ;-)

  • I upgraded to Firmware version:9.703-2. My environment consists of HA (master/slave) in Vmware, so I made a snapshot to revert if it didn't work. However, I have not seen any problem so far (2 days, so far). Perhaps the problem is related to some functionality that I am not currently using!? I am currently using Sophos AP55C for wireless, two VMs for HA, web in transparent mode, vpn ssl, a couple of virtual nics for different interfaces, a couple vlans, basic firewall, and the UTM as dhcp and dns. Thanks, Martin
  • In reply to zaphod:

    zaphod

    they want to push the XG so UTM isnt the focus. i miss the good old ASG times when you can call a astaro developer directly when you find a bug  in fw, mostly 1 hour later you got a fix ;-)

     

     

    Same here.

    Sophos turns this thing more and more in an unreliable peace of software, that extremly sucks.

     

    And i dont wanna switch to XP, which is worse then UTM.

     

    So can i have Astaro back, please ?

     

    cheers from Germany

  • In reply to zaphod:

    zaphod

    they want to push the XG so UTM isnt the focus.

    Well, current XG update 18 MR1 has identical problems:
    https://community.sophos.com/products/xg-firewall/b/blog/posts/xg-firewall-v18-mr1-is-now-available
    https://community.sophos.com/kb/en-us/135378

    Seems Sophos pushed in the wrong direction... Wink

     

    Quality management at Sophos seems kind of up and down. 6 months OK, then six months bad, and so on...

  • In reply to scorpionking:

    One thing I really don't understand: why is there no easy way to revert to the state before the update? There should be a second copy of the (old) firmware which one can easily switch back to, if anything goes wrong. Even if I do kernel updates on linux systems I always have the possibilty to start with the kernel version I had before, instead of completely seting up the system from scratch and upload a config-backup I hopefully made before to another place outside of the system.

  • In reply to twister5800:

    twister5800 wrote the following post at 17 Apr 2020 9:18 AM:

    Reformat with 9.702 iso and restore backup file :-/

    -------------------------------------------------------------------------------------

    Wish we could do that...

    May I call your attention to this suggestion made over 2 years ago? Implementation of this feature would have saved our butts with Sophos' current screwup!

    We've been running an SG 230 Rev. 1 for a number of years and were quite happy with it - until we purchased a second SG 230 and stumbled across the a. m. issue Thorsten had discovered. This rendered our new Rev. 2 machine totally useless. We couldn't use it for HA or as a backup machine. The "Premium" support we contracted was no help at all ([#8609926] Backup email addresses of users registered for SPX -- Priority: Medium -- Level: Premium 25. Februar 2019, 13:34 Uhr):

    as stated in the previous emails, the functionality you requested is not and will not be provided by Sophos UTM for the foreseeable future.

    Until that day we had believed that  "Create Backup" meant saving everything needed for a COMPLETE restore - but obviously "unique site data (license, passwords, certifcates/keys)" does not entail the SPX email accounts and PWDs.

    We have roughly 1.500 SPX accounts which need to be transfered from our shot Rev. 1 system with 9.703-2 to our up-and-running Rev. 2 machine with 9.702-1.

    Any suggestions? (How) Can we transfer the SPX database files from one appliance to the other? Can we revert to 9.702-1 without losing said SPX data?

    Thanks & best regards,
    Wilfried

  • In reply to wrj:

    Hallo Wilfried and welcome to the UTM Community!

    I can't believe that no one at Sophos knows where those keys are stored.  Have you tried opening a case with Sophos Support?

    Cheers - Bob

  • In reply to BAlfson:

    Sorry, Bob,

    that has been our experience. Our sorry experience has cost us € 1.700 so far.

    Here's the timeline:

    2019-12-18 we order our second SG230
    2020-01-08 we run into the SPX PWD problem and contact our supplier
    2020-01-19 they cannot help & refer us to Sophos directly
    2020-01-25 we order 1 yr. Sophos "Premium Support", the above mentioned ticket is started
    2020-02-14 they tell us that "currently SPX registered recipients cannot be saved or included in the backup" (I call that a bug, not a feature request)
    2020-02-25 the ticket is basically closed by Sophos Premium Support with the following statement & suggesting more paid help by their Professional Service Team:

    I can neither confirm nor negate whether a partial port of the corresponding database table is possible (and whether support for any problems resulting from this is still guaranteed).

    Our management was not inclined to "chase good money after bad", so we left it at that. Case closed.

    Until Sophos nuked us all with 9.703-2 ... So, is there anybody out there who can help?

    Best regards,
    Wilfried

  • In reply to wrj:

    Hi Wilfried,

    maybe (but really maybe) a short look in the REST API can help to get your SPX recipients back.. but only if you have a machine with the old database running and useful to get REST calls running on it. as far as i read if you run into this bad firmware bug the machine becomes usesless after short uptime :-(

    hope others has suggestions to help you fix this out.

     

  • When will a fix probatly released?

    I have some medical instution as customers, who already patched to 9.703 and now we have some major issues. Like massive ping drops via RED UTM to UTM tunnel.

    As we can not simply take them down and reinstall, as this would affect to much services..

    Now they have a problem with voice as this transits via the RED tunnel.

     

    Any news on the fix yet?

  • In reply to wrj:

    The database file with the spx data should be: /var/storage/chroot-smtp/spx/auth/spx-auth-v2.ks

    Regards,

    Marco