XG Firewall v18 MR-5: Feedback and experiences

Top Replies

  • The classification process is still broken - ntp, Imaps.

    Is there any reason at all on why the Firewall can't detect NTP traffic as Its own application?

    Creating a application signature…

  • Waiting for the user to stop, so I can try out the update.

    ian

    installed. I still can’t get yahoo mail to verify. Yahoo smtp server fails certificate checks. More testing tomorrow morning and see what joy the reports bring.

     
    V18.0.x - e3-1225v5 6gb ram with 4 ports - 20w. 
    3 AP55s and 2 APX120s having a holiday until software update is released.
    If a post solves your question use the 'This helped me' link.
  • I want to save you some time: 

    SSLVPN + WAF Portsharing: You can share the port of the SSLVPN and the WAF on 443. But not the same protocol (UDP/TCP). WAF is always TCP, so you can use SSLVPN UDP on the same Interface/IP. You can also use SSLVPN on TCP. There is no Interface selection in SSLVPN, it will be activated on every Interface. If there is a WAF/DNAT, it will overwrite the SSLVPN. 

    SSLVPN (Sophos Connect) needs a User Portal settings. In XG, user portal and SSLVPN can share the same interface (Both TCP 443 for example). But User Portal runs on TCP and will block the WAF. So thats not possible to run on TCP443. 

    About the Missing Heartbeat: The switches to setup this missing heartbeat config: 

    console> system synchronized-security
    delay-missing-heartbeat-detection      suppress-missing-heartbeat-to-central
    console> system synchronized-security delay-missing-heartbeat-detection show
    60
    console> system synchronized-security suppress-missing-heartbeat-to-central show
    0  

    __________________________________________________________________________________________________________________

  • But not the same protocol (UDP/TCP).

    Couldn't the Sophos Devs use the "port-share" parameter for OpenVPN? This would allow both WAF and SSLVPN to share the same TCP port.


    If a post solves your question use the 'Verify Answer' link.

  • Thats not possible. The Packet flow does not work in XG that way. WAF/DNAT will be first. Hence the Portshare would require to be implemented within the WAF (Kernel) to share this to the openVPN stack. OpenVPN port-share is a option, which will forward certain traffic to another instance. That would require a complete revamp of the architecture. 

    __________________________________________________________________________________________________________________

  • On my XG Home system MR-5 took an enormous amount of time to boot post upgrade (30 minutes) whereas usual MR updates take 5 minutes or so.  I am using the software version of course.  Other than that everything seems ok.  

  • You mean the upgrade process after the reboot took long time to get to the stable mode? Do you have a serial output of this? 

    __________________________________________________________________________________________________________________

  • Yes after reboot it took 30 minutes to come back up.  I have no serial output, just an observation.

    EDIT: Upgraded an XG135 hardware appliance, it worked fine, several minutes to reboot after update and come online.  Guess it was just something with my home rig.  

  • Is there any reason that SSLVPN will be activated on every interface? Why is it not possible to use different external IPs for WAF and SSLVPN/User Portal, so that both can use 443 TCP on their own interface/IP?

  • SSLVPN + WAF is not the issue. It will work like you explained. Only the User Portal can cause issues, as it cannot be used in such deployments on 443. User Portal will blocked by the WAF and cannot be selected on a specific port. 

    __________________________________________________________________________________________________________________

  • Reports are still bad, yesterday's download of mr-5 to my mac does not show.

    The classification process is still broken - ntp, Imaps.

    Mail scanning is still broken, over 6000 messages for two people in one day.

    Ian

     
    V18.0.x - e3-1225v5 6gb ram with 4 ports - 20w. 
    3 AP55s and 2 APX120s having a holiday until software update is released.
    If a post solves your question use the 'This helped me' link.