Hi XG Community!

We've finished SFOS v17.0.3 MR3. This release is available from within your device for all SFOS v17.0 installations as of now.

Besides that, the release is available to all SFOS version via MySophos portal.

Issues Resolved

  • NC-25584 [IPsec] IPsec tunnel frequently gets disconnected after migration to v17
  • NC-25597 [IPsec] Disabling DPD has no effect
  • NC-25641 [IPsec] Improve IPsec failover behavior
  • NC-26024 [IPsec] Change default "Policy Keying Tries" to unlimited
  • NC-26032 [IPsec] Too many email notifications on connection retry
  • NC-25986 [Logging] Fixed CVE-2017-18014
  • NC-23214 [Wireless] XG105w failed to update channel width 80 MHz for 5Ghz band

Downloads

You can find the firmware for your appliance from in MySophos portal.

Parents
  • Sophos, you are doing a very poor job at testing your firmware before releasing to the public. Every single time I have upgraded to a new firmware we have had various issues. This latest firmware immediately shows it has bugs with VPN in an HA cluster, where the tunnels are up but the status shows as down, or that phase 2 is down. We have switch 80% of our firewalls from Fortigate to Sophos, and every firmware upgrade we apply I increasingly regret making the switch to your product. We are told that there won't be a fix on this until MR-5 when the current firmware is MR-3. All I can say is that thankfully we are not running these in our hosting facilities because our customers would be furious.

Comment
  • Sophos, you are doing a very poor job at testing your firmware before releasing to the public. Every single time I have upgraded to a new firmware we have had various issues. This latest firmware immediately shows it has bugs with VPN in an HA cluster, where the tunnels are up but the status shows as down, or that phase 2 is down. We have switch 80% of our firewalls from Fortigate to Sophos, and every firmware upgrade we apply I increasingly regret making the switch to your product. We are told that there won't be a fix on this until MR-5 when the current firmware is MR-3. All I can say is that thankfully we are not running these in our hosting facilities because our customers would be furious.

Children
No Data