Hello,
The XG210 of my Custommer crashed today at 8:50AM, we were not able to ping the LAN IP or the WAN IP.
The firmware version is 17.1 GA.
It came back after a manual reboot.
Once online again I saw in the "performance" tab that we had an anormal high number of sessions at 8h50 which I guess it's the cause why the firewall crashed.
I don't really know what can cause such a high number of sessions, in normal use the sessions number is between 300 and 600 on this firewall...
Any advice ?
I opened a case with the number: 8183274
Viken
*UPDATE*
The high number of sessions is not the cause of crash because it not happened before the crash but when we rebooted the firewall.
During the crash the number of sessions is stuck at 0.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
Hi Viken,
Take a look at the KB article we published here. You might be affected due to this issue.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Hello Sachin,
Unfortunately this KB doesn't concern my case because the XG210 is not in HA.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
In that case, could you tell us the number of concurrent active users behind the XG Firewall and which modules are actively used for filtering the network traffic.
Alongside, PM me the syslog.log to investigate further. Finally, do you see high CPU and high memory utilisation on the XG device?
Thanks,
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Hello,
I think the XG210 is oversized for the way it's used by the company. There are 40 users behind the XG210, and the XG210 is connected via SSL VPN SITE-TO-SITE on a XG125 and there are 10 users behind it. So there is 50 users max using the XG210. The license used is EnterpriseProtect. The modules activated are WebFilter and ApplicationFilter, IPS, STAS, Wireless Protection with 3 AP55.
The CPU and memory utilisation are very low on the XG210 device. The CPU is constantly less than 10% and memory constantly less than 35%.
Where can I find the syslog.log and how can I transfer it ?
Thank you.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
Refer to the following KB article for the log file information, https://community.sophos.com/kb/en-us/123185. You can copy the logs to the clipboard of set up putty to store the log lines in a text file. PM me these log lines and I will add my inputs.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
I sent you the logs via PM.
Thanks.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
I had a similar experience.
My XG 230 running 17.1 GA hot a Load Average of above 15 which made the CPU get stuck at 98+%
I had to pull the plug and reboot it to get it back. It too reports high CPU. Only since 17.1 was loaded though.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Hello,
Mine did not crashed since my post.
Hope that it won't anymore.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
Mine hasn't either.
I had the Sophos Support team jump in and run through the logs. We can see when I rebooted it but for 30 min before - when CPU was high there were no logs showing anything bad.
The XG just went nuts for no reason.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
The Sophos support just called me back today to connect on the XG and have a look on this crash.
They told me they will escalate the case at the lvl 3 because they couldn't find anything in the logs.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
All I got from support was to perform Hardware, Memory, and Disc checks.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Sadly mine crashed yet again - this time no CPU load etc - just stopped and died.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Sad...
Mine did not crash since the initial crash and lvl 3 engineers are still investing on the issue.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
Mine crashed yet again today.
Logging etc was fine until the crash when it just stopped - no errors etc.
Sophos are now RMA me a new one as they think it might be a Hardware failure due to the way logs just stop.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
We have had one of our XG210s (lightly loaded) crash yesterday about 15:45, with 17.1.1 MR-1, hard rebooted today as even ssh terminal will not log in, GUI died 1hr or so later, ssh cannot login as well so downgraded to 17.0.8 MR-8
It had been running 17.1.1 MR-1 for over a week with no issues so I think an update sent yesterday has caused this.
Hello, I also have the XG210 and today I became the same problem around 11:45 pm in the Czech Republic. Firewall has stopped responding I had to manually shut down. I have SFOS 17.0.8 MR8
Excuse me for my English ...
Hi,
Can we try to find a pattern?
Can you please post your Fabric date of your XG210?
__________________________________________________________________________________________________________________
Hi,
Where can I find Fabric date of my XG210? Will you get a serial number C23076JBFP7MC92 ?
All I can say is my XG230 was Manufacturer date Oct 2015 Rev 1
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Should be a sticker on the appliance itself.
__________________________________________________________________________________________________________________
Hmm, ours crashed 3 more times over the weekend, even when downgraded to 17.0.8 I think it must be a broken patch/pattern as 17.0.8 and 17.1.1 were stable until the middle of last week. I'm going to log a support ticket today as this is simply unacceptable. Unfortunately I cant get something off a sticker as ours is 100 miles away in a remote site with no techs there...
I had Sophos Support replace mine - I have an RMA one here to put in my Comms rack tonight.
Not sure if its any help but my support ticket is:
# 8273744
I had 3 other tickets before this for the XG Crashing. All since going to v17.1 (coincidence?)
The last ticket Sophos think I may have a corrupt disc as when the XG stops it Stops Dead - no logging etc just goneski.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
I could remove the XG210 from the rack and it is not possible. I still have a paper box where these values are. Sophos XG210 rev. 3 Security Appliance. SKU XG21T3HEUK
Ours had a corrupt disk as well and was RMA replaced. We got a rev2 to replace a Rev1 so I think 17.1 corrupts Rev1 drives...
Jumping in here, an XG 105 (rev2) at a customer of mine began having similar issues on 8-16-18 at around 9:40am Pacific Time. The customer called me and told me their internet access was down. I couldn't access it. Had them hard reboot it. Happened twice that day and once the next day. Can't stand it. I'm on an older 16.05.8 firmware for legacy VPN reasons... but thought I would throw my notes in here just in case it helps. I don't know if my issue is the same, but I have not had a single outage for the past 8 months since I installed this unit, and now this.
Opened a support case 8300357, we looked at logs and at system performance charts. My RAM and CPU usage literally dropped to 0 from about 8-16 at midnight until about 8-16 at 10 am after the unit had been shut off and on. So nothing was logged at all the entire morning for performance. One time I was able to get into the GUI, and CPU was hovering around 99% for unknown reasons.
Support did a tail command and could see failing antivirus updates. At the moment I have no resolution. Did a memtest, disk check etc.
I've restored to a backup as of 8-1-18 but I'm not hopeful as I think the pattern updates remain even after a (config) restoration from backup.
Bummer!!
I was blaming 17.1 but you are not on that (you should be - much better than 16)
My logs were similar - all cruising then max CPU and lock up. No network, SSH etc and the logs show nothing at all.
The XG just stopped.
I have a replacement unit now so fingers crossed it remains up.
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
You had mentioned there were no hardware errors found, so I wonder if there is just no way to fix a bad pattern installation without sending a new unit? New unit sounds nice but, Support told me last night that if the crashing/freezing is in fact being caused by a pattern update, that a simple config restore won't be enough and that the only way to fix it is a full firmware wipe which is surprising to me. Does any one know if it's in fact not possible to just revert back a bad pattern update?? Or even know which one caused it?
I had no pattern updates stuck.
Sophos support couldn't find any reason at all why my XG would crash. Nothing stuck, nothing logged etc - just ceased to function.
This is why they decided it might be a bad disc and replaced the XG
Its been up for less than a week now and I also updated it to 17.1.2 MR2 - fingers crossed as mine crashed about every 10 days
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
I put my RMA right onto 17.1.2 MR2 as it was just out.
No issues so far and another thing I noticed was I was getting Performance warnings for Load average on my original one where as the RMA doesn't get the spikes I was getting.
So maybe I did have a bad disc and when it was being accessed caused a higher load time.
Still hoping it remains up.
I downloaded 17.1 and 17.1.2 directly from MySophos and not via the GUI
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Mine did not crashed again since the 1st crash. It is now running with 17.1.2 MR2 and all is OK.
Viken
XG Certified Architect
Sophos Gold Partner - Reseller from Lyon, France
Mine has remained up since Sophos Replaced the Hardware.
Looking more like I had a bad disc causing mine
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....