Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[SFOS 18.5MR3] Poor spam detection after update to Sophos Anti-Spam Interface

Hi everyone,
I am setting up a separate thread as I did not receive any specific reply in other threads.

The case concerns Sophos Anti-Spam Interface after upgrading from v18.5MR2 to v18.5MR3 and from v19EAP1 to v19EAP2.

Before updating, antispam works great in legacy mode, detects a lot of intrusive messages and tags with a prefix (near 99%). After updating, only some messages are detected as spam and tagged (I did not do any changes in configuration).

What it comes from? How can I edit my lists to achieve pre-update spam detection?

Greetings



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Emmanuel,

    the u2d.log is 34mb, there are no entries in EML with the X-SASI-*. I checked valid and spam messages. Both logs files you have requested are dated  at 0850 this morning.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Emmanuel,

    Do you still want copies of the files even though there is no X-SASI-* in the EMLs? Or do I wait until v19 has been released as GA?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Helo rfcat,

    Thank you for the follow-up.

    Yes, and if you have any other emails coming since 3 days ago that are SPAM. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • I have spam mail, but they do not contain any X-SASI entries.

    I will capture the files and forward them to you.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Emmanuel,

    have sent you the requested files in two PMs

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, any news about investigation? I had reverted to MR2, because spam tags are very useful for me.

  • Since the update on March 31, 2022, the following error messages have appeared in the log.

    SFV2C4MSP_VM01_SFOS 18.5.3 MR-3-Build408# cat /log/sasi.log | grep ERROR
    2022-03-31.22:33:57 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.02:18:08 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.05:22:14 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.06:40:46 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.07:16:21 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.07:18:28 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.08:44:49 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:08:14 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:11:09 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:16:40 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:54:54 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.10:40:28 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:49:19 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:56:02 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:57:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.13:06:41 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.13:42:38 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.13:59:26 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.14:55:23 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.15:30:50 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.16:45:15 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.16:57:17 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.16:58:40 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:42:26 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:43:47 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:45:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.22:11:54 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.22:13:13 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.04:54:28 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.07:38:46 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.08:51:51 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:31:53 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-02.12:02:01 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.13:56:08 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:00:20 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:40:21 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.23:24:32 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-03.08:13:06 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.12:08:41 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.12:13:15 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.12:25:25 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.12:26:40 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.13:28:23 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.14:07:27 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.14:37:20 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.14:45:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.15:17:22 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.20:20:58 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.21:01:37 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.21:41:38 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.22:21:39 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-03.23:01:40 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.00:45:45 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.06:29:55 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.07:09:56 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.08:19:45 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.08:30:05 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.09:39:37 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:09:08 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:13:38 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:42:33 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.11:04:32 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.11:18:15 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.14:07:38 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.15:13:15 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    SFV2C4MSP_VM01_SFOS 18.5.3 MR-3-Build408#

  • got these errors:

    SFVH_SO01_SFOS 18.5.3 MR-3-Build408# cat /log/sasi.log | grep ERROR
    2021-12-07.23:34:07 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: downloads.sophos.com/.../asdb.antispam.old.csum
    2021-12-07.23:50:08 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: downloads.sophos.com/.../asdb.antispam.old.csum
    2021-12-08.13:27:57 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-08.13:34:08 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-09.13:44:09 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2021-12-09.14:24:13 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2021-12-09.20:48:36 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-09.21:28:39 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-10.14:24:46 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-11.00:50:11 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-11.05:07:22 ERROR [ 1] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-11.20:27:13 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-24.21:09:45 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-24.22:29:50 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.01:58:04 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2022-03-25.04:14:18 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.06:38:33 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.07:18:32 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-25.08:14:38 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.13:55:49 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-25.21:11:39 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.22:31:45 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.02:16:02 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.08:00:35 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.13:04:54 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.13:44:56 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.00:33:44 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.17:50:59 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.18:31:02 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.20:31:10 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-28.04:39:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.07:20:00 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.11:44:20 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.23:53:15 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.09:21:58 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-29.13:06:17 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.18:50:54 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.19:30:57 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.20:25:14 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-29.21:31:05 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-29.23:55:16 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-30.06:59:49 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-30.18:18:03 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-31.02:46:11 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-31.08:45:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.09:25:51 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.10:05:52 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-31.17:10:25 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.21:26:53 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.01:59:06 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.11:27:48 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-01.18:32:23 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.23:44:46 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:13:30 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:53:31 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-02.16:58:05 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.17:38:07 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.18:18:10 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:22:13 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2022-04-02.22:42:31 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.00:18:51 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: sasi.sophosupd.com/.../asdb.antispam.old.csum
    2022-04-03.22:20:20 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.22:44:20 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.04:28:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.05:35:33 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.13:57:32 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.17:40:29 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    SFVH_SO01_SFOS 18.5.3 MR-3-Build408#

    Bart van der Horst


    Sophos XG v18-v21 Certified Architect

  • 2022-04-04.18:20:31 ERROR [Main] [ precompile.cpp:647] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.18:21:22 ERROR [Main] [ laseserver.cpp:159] Couldn't fetch new signatures: Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.antispam Exiting..

    Bart van der Horst


    Sophos XG v18-v21 Certified Architect

  • SFVH_SO01_SFOS 18.5.3 MR-3-Build408# tail /log/sasi.log -F
    Failed to run server: Couldn't fetch new signatures: Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.antispam Exiting..
    2022-04-04.18:26:38 MESSAGE [Main] [ main.cpp:78] LASE Daemon STARTED
    2022-04-04.18:26:38 MESSAGE [Main] [ main.cpp:80] LASE Daemon Version: 4.1.4
    2022-04-04.18:26:38 MESSAGE [Main] [ laseserver.cpp:372] Lased started on port : 25315
    2022-04-04.18:27:42 MESSAGE [Main] [ main.cpp:78] LASE Daemon STARTED
    2022-04-04.18:27:42 MESSAGE [Main] [ main.cpp:80] LASE Daemon Version: 4.1.4
    2022-04-04.18:27:42 MESSAGE [Main] [ engine.cpp:306] Signatures don't exist, fetching new signatures..
    2022-04-04.18:27:44 MESSAGE [Main] [ precompile.cpp:580] Downloaded file /sdisk/sasi/asdb.antispam is verified with checksum..
    2022-04-04.18:27:44 MESSAGE [Main] [ engine.cpp:362] New signatures are downloaded and validated.
    2022-04-04.18:27:44 MESSAGE [Main] [ laseserver.cpp:372] Lased started on port : 25315

    I deleted all files in the /sdisk/sasi dir and restarted the antispam service

    No he says the correct asdb.antispam is loaded

    Bart van der Horst


    Sophos XG v18-v21 Certified Architect