Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Hi Lucar,

    I've managed to replicate this with a brand new virtual machine. If possible, keep us updated if you have any new information about this.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • This will be addressed with NC-76446 in the actual MR1 release (GA). There will likely be another build published with this fix included. This will be addressed in the release notes. 


  • IPS/DOS is still broken. Something during v18.0.4 b broke IPS/DOS and has not been required in later releases.

    I have tried multiple ideas on settings and the only setting that works is disabling IPS/DOS. One security camera will load without triggering IPS/DOS but when I try to load all 4, only one loads and the others either timeout or disconnect.

    I have tried with the web proxy, DPI and neither no change to the ability to connect when IPS/DOS is enabled. The logviewer shows nothing in the IPS view but lots of either DOS on port 53 or broadcasts.


    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Try a DOS exception for such devices, if you do not want to increase the numbers of the particular device.


  • Thank you.

    I would expect the DOS bypass process to be a temporary fix until the DOS process is fixed.

    i tried that in v18.0.5 586 and came to the conclusion that the bypass process does not work. You end up with a log of hundreds of valid connections to external DNS devices. The connections never actually complete to the security cameras.

    I tried individual rules and network rules with the same result, no stable connections if the connection established. Also there are a large number of failed DHCP requests.

    I do not see the same number of entries when I disable the DOS settings.

    Also the DOS bypass process is a bit ancient, eg no dropdown lists to select networks or devices or even protocols (service).


    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • ,

    Is there any news on NC-59127 for v19?, the original thread I've made about It back then got locked because of old age.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • Is there any plans for HTTP/2 support in the future while doing TLS Decryption over the DPI Engine?

    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • Thanks,

    upgrade was fine on my LANCOM UF-200 Firewall, i upgraded from 18.0.5 to 18.5 MR1.
    No Problems so far, i need to test if IPv6 will work now with Deutsche Glasfaser.

    They have a bad IPv6 implementation. They don´t have RA implemented correctly. RA´s are send randomly...

    I need to see if the 32GB SSD and 4GB will be enough ... 

  • The support of Intel based chips within Sophos SFOS is still on the backlog. We are still looking into this and the impact of implementing this. But i am assuming V19.0 is not the target release for this yet. More answers if ready to publish by Product management. 


  • Wow. That’s disappointing to say the least.