This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG V18 MR3

Hello Sophos,
can we still expect the XG V18 MR 3 this week ?




[locked by: FloSupport at 4:35 PM (GMT -7) on 13 Oct 2020]
Parents Reply Children
  • Think we have to wait one more week...

  • I can only recommend you one thing ... Don't.  v18 is mostly about two things.  Decoupled NAT, and TLS/SSL Inspection rules.  The later does not work.  Source of continous problems and slowing down everything to a crawl.  You can live with coupled NAT. So. Wait at least another year.  Seriously.  Other wise you'll be part of Sophos Q&A team liking it or not.  And your customers will want to hang you.

    Paul Jr

  • Or maybe It will be out this week, there will be a webinar talking about v18 MR3 next Monday.

    Technical Update Session

    The next Technical Update session will occur on Monday, October 12, 2020 at 3:30pm (CET).

    Agenda:

    • Introduction
    • Most recent product updates:
      • Sophos Connect 2.0
      • XG Firewall v18 MR3
      • New APX Access Point
    • You asked – we deliver: Live demo of Synchronized Security
    • Q & A


    More info at Sophos Partner News.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • is right about the TLS/SSL Inspection Rules; it just doesn't work.  You will pull your hair out trying to troubleshoot why sites randomly either fail to load or load extremely slowly.  Loved getting the panic call from our HR people who couldn't process payroll because the site wouldn't load halfway through.  The answer you'll get from Sophos is "Make an exception" but when you observe that somewhere around 30% of sites have problems, that's not a practical or realistic or serious answer.  

    Part of the reason I've been so interested in MR3 is the hope that there are major improvements to the TLS/SSL engine, but I'm not holding my breath anymore.  

  • Make exception rules was what I was told too.  If you look at Sophos own built-in exception rules (for Microsoft updates for example), you'll notice that many of them disable ssl inspection very widely to a point it is not usefull anymore.

    Paul Jr

  • I got a Webinar today with the following topic: "What was in MR3 and is coming in MR4"

    Maybe I can provide some more here after it.

  • I hope they have some good stuff planned. 

    It took them forever to get it done. 

  • most probably fixing the typos that were made by a previous dev that is no longer working for Sophos.

    XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)
    Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!

  • Hello Argo,

    I'm afraid they would have to fire everyone who had anything to do with a firewall rules, NAT rules and TLS / SSL rules too.
    So is it about half of all developers?
    I think they would definitely deserve it, but I'm afraid it didn't happen ....

    Regards

    alda

  • Sophos retrenched about 150 staff earlier this year.

    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.