Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Could not import the configuration from the selected firewall - Sophos Central

Im a bit lost in this; see a lot of potential in managing the XG firewalls from Sophos Central (we also use it for Endpoint, wireless, encryption, etc).

Adding the XG to Central was easy, so was accepting. Then I tried to create a a firewall group and would like to import the config from the existing firewall. When choosing the firewall and clicking save the process starts. After some time it will give the message:

Could not import the configuration from the selected firewall. with a red exclamation mark in front of it.

I can however perfectly manage the firewall through Sophos Central so connection seems fine.

It may have something to do that at this moment the firewall I am configuring is still behind a UTM hence behind a NAT device and it may need to have some ports opened, however that imho would defeat partly the power of Central management.

How can I troubleshoot what goes wrong with this import?



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    What is the firmware version on your firewall?

    I was able to take the configuration backup from the Central for the firewalls running with v18 MR4 and v17.5 MR14. These firewalls are behind the UTM. 

    I experienced the same issue as yours on v17.5 MR14, but it worked after I re-registered the firewall with the Central. 

    Thanks,

  • This is on V18.0.4 MR-4. Registering in Central was also done after upgrading to MR-4.

    Making a backup is not the problem, but when creating a group at the point "Select an initial configuration for your group. You can customize it later" when I choose to import from current config, than it runs for a while, it does create a handful of dynamic objects, but I suspect it fails halfway the proces.

    It also shows different then a group created with Sophos defaults (see screenshot):


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • There are some bug IDs, currently under investigation, which could prevent the Import.

    Just to name some blockers in the Configuration:

    Do you use a WAF Rule? This could block the import. 

    Do you have a Zone under Device access, which does not have select "ANY" services? This will block the import. 

    Those issues will be fixed in a upcoming Central version. 

    __________________________________________________________________________________________________________________

Reply
  • There are some bug IDs, currently under investigation, which could prevent the Import.

    Just to name some blockers in the Configuration:

    Do you use a WAF Rule? This could block the import. 

    Do you have a Zone under Device access, which does not have select "ANY" services? This will block the import. 

    Those issues will be fixed in a upcoming Central version. 

    __________________________________________________________________________________________________________________

Children