Parents Reply Children
  • It is not that easy to integrate a Hardware support for AES-NI. And currently the same team is working on improvements for XGS hardware and the integration of more technology to the Sophos own chip. 

    __________________________________________________________________________________________________________________

  • Guess my use case is somewhat unique yet I’m sure also common. I have a home license but using Sophos hardware. To use the home license I have to install the software version and because of that I miss out on AES-NI. 

  • Hi,

    why do some Sophos firewalls (using intel CPUs) have AES-NI and others don't, it really should be a switch in the compiler, the integration has been tested over many releases?

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Is there any reason at all on why the Devs prefer to only patch for vulnerabilities instead of update the underlying open source software such as SSLVPN (OpenVPN), or WAF (Apache)?

    The Firewall could have AES-GCM and TLS 1.3 support for SSLVPN if OpenVPN has been updated.

    Or even HTTP/2 and TLS 1.3 support for WAF.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • There is a difference. You cannot simply update a openVPN tool and "hope" it will works. And you need openssl to update first. Which is a much more difficult. OpenSSL is a module used in all modules. As you can see, there are multiple dependencies. This is the reason, openssl 1.0.2 still exists in a LTS. Vendors have difficulties to open such a module. But Sophos is commited to tackle this for the future. 

    __________________________________________________________________________________________________________________

  • Thanks a lot for the answer!

    Hopefully some of those packages get updated in the future.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Will there be a v19 EAP in the future?


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Yes - ETA is to be announced. You will see the EAP as usual in the community, once it is ready. 

    __________________________________________________________________________________________________________________

  • Will it still be announced this year or 2022?


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • I cannot comment on that, as i am not a product manager. 

    __________________________________________________________________________________________________________________