Hi XG Community!

We've finished SFOS v17.0.3 MR3. This release is available from within your device for all SFOS v17.0 installations as of now.

Besides that, the release is available to all SFOS version via MySophos portal.

Issues Resolved

  • NC-25584 [IPsec] IPsec tunnel frequently gets disconnected after migration to v17
  • NC-25597 [IPsec] Disabling DPD has no effect
  • NC-25641 [IPsec] Improve IPsec failover behavior
  • NC-26024 [IPsec] Change default "Policy Keying Tries" to unlimited
  • NC-26032 [IPsec] Too many email notifications on connection retry
  • NC-25986 [Logging] Fixed CVE-2017-18014
  • NC-23214 [Wireless] XG105w failed to update channel width 80 MHz for 5Ghz band

Downloads

You can find the firmware for your appliance from in MySophos portal.

  • My RED XG to XG Tunnles ar all in various times offline. Reboot or so do not help! I must delete and recreate all of my RED tunnles to get them working again.

    Thankfully i have installed 17MR3 only on my Home XGs and not on the XG of our Company...

    Hint@Sophos: Think about making XG stable and than making it the fastest firewall in the world. This would help us all....

  • Hi,

    I recently upgraded to v17 MR-3 and i found out that i am unable to delete any local user from xg. i then created a new user manually and immediately tried to delete that user and i get the error that cannot delete user as it is already being used by some firewall rule, web category or vpn connection.

  • Still no update on IPSec except an advisory from Sophos

    community.sophos.com/.../128108

    Since V17 there has not been a working IPSec VPN

    This problem is now more then 3 months and still no solutions!

  • please read the Advisory (do not upgrade!!)

    community.sophos.com/.../128108

    why wait for more then 30 days to bring this advisery after all the complaints

    MR3 releas = 20 Dec 2017

    Not only MR3, but since V17 NO MORE stable ipsec

  • Sophos, you are doing a very poor job at testing your firmware before releasing to the public. Every single time I have upgraded to a new firmware we have had various issues. This latest firmware immediately shows it has bugs with VPN in an HA cluster, where the tunnels are up but the status shows as down, or that phase 2 is down. We have switch 80% of our firewalls from Fortigate to Sophos, and every firmware upgrade we apply I increasingly regret making the switch to your product. We are told that there won't be a fix on this until MR-5 when the current firmware is MR-3. All I can say is that thankfully we are not running these in our hosting facilities because our customers would be furious.