We'd love to hear about it! Click here to go to the product suggestion community
I got information from my UTM that a new firmware 9.601-5 was available. I installed it and after reboot I discover that all my NAT rules where not activated ! I had to go on each one and disable/enable them to get back the working setup :(
I did it with some of them and then reboot the UTM: again rules where not applied. Disable/enable them and evrything is OK.
For some rules I didn't apply the "automatic firewall rules" in GUI but had create myself the FW rules: those NAT rules where activated. But for NAT rules with forwarding ports to other physical hosts but *not the host himself and the VMs running on it where the UTM lies* doesn't matter which setup (manual or automatically), I have to activate "automatic FW rules" and disable/enable the rules to get them working.
No need to say that prior firmware versions didn't had this problem.
Does anyone face the same problem and confirm?
In reply to Daniel Huhardeaux:
Daniel Huhardeauxthis morning I got answer from Sophos France support: working on our logs they found the problem which should be resolved with version 9.7 expected current october.
9.7 seems to be pre-release ; I cant find an English readme or bugfix
Has anyone with access to 9.7 got confirmation on whether this is fixed yet - I have dozens of UTMs ready for updates but I am unwilling to update them if I then need to login to each one manually and STOP/START NAT Rules!
In reply to GrantAU:
Sophos seem to have acknowledged it in KB Article 134544 :
I can confirm not fixed in 9.700-5
Thanks for the feedback.I guess I will have to do it manually for a while again...Regards,DeltaSM
In reply to DeltaSM:
If you don't want to wait till a solution is published you can set yourself FW rules and disable the "automatic create fw rules" switch.
Daniel - thanks for that info - I wasn't aware you could do that - I may need to do that to some of the clients who seem to need to reboot their UTM often (usually to get 4G USB Dongles to "reconnect") - but doing this to all my client devices will take hours and is just not possible. Sophos should fix this.
Issue still present in release of 9.7
As a reseller/partner I lodged a support request with Sophos AU that "This was supposed to be fixed in 9.7 - I have just updated some client devices to 9.700-5 and this issue is still present in these devices" -
I heard back 6 days later :
"Appreciate your patience we checked as mentioned in the KB the issue will be resolved in the UTM firmware version 9.7 which is already released. Would request you to please update the firmware version to 9.7 to resolve the issue"
So, nothing done yet - and I am not sure why they think it's fixed, when it clearly isn't.