<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/134114/xgs-stopped-working-18-5-3</link><description>(2) Sophos XGS4500 (SFOS 18.5.3 MR-3-Build408) HA I was wondering if anyone has seen this issue. Yesterday our XGS just stopped passing traffic (nothing would go through). The XGS was accessible internal (web interface and ssh) and was able to communicate</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/501506?ContentTypeID=1</link><pubDate>Wed, 27 Jul 2022 08:26:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a1aec510-6c1d-4255-86de-8a7760d9843b</guid><dc:creator>Andreas Hahn1</dc:creator><description>&lt;p&gt;We were able to solve our problem, it was the IPv6 DHCP server. The problem has occurred in all versions from 18.5.2&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495055?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 13:42:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4a5f6cb0-cbac-49bb-8b05-c9361cf994d5</guid><dc:creator>JasP</dc:creator><description>&lt;p&gt;This site had an XG for a couple of years without any issue. It sat behind a Cisco router. The Cisco router terminated the WAN connections and provided client and site to site VPNs.&lt;/p&gt;
&lt;p&gt;We replaced that solution with two XGS in HA and terminated the WAN connections and client and site to site VPNs on the XGS (completely removing the Cisco router). The rest of the config remained the same. Problems started within a week of making the change.&lt;/p&gt;
&lt;p&gt;I did mention this thread to our support engineer. He said that the problems were too generic to know if they are the same issue we are experiencing. It is worth bearing this in mind. We may not necessarily all be suffering from the same route cause.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495039?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 12:24:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7a532e4b-eac5-46c9-8535-1d4e7d7d4fd8</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;OK, so it is mixed hardware. Too bad.&lt;/p&gt;
&lt;p&gt;I remember we had an issue where a specific config change caused XG HA to become unresponsive and at some point did not pass traffic until the HA Aux (yes, the slave node!) node was rebooted.&lt;/p&gt;
&lt;p&gt;Is it possible that this issue begins with any config change? Check Admin audit log for changes and then HA logs if they match together.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;in our case we could see this starting when we did the config change:&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;br /&gt;==&amp;gt; /log/ha_tunnel.log &amp;lt;==&lt;br /&gt;Mar 02 18:16:40 ssh: connect to host hapeer port 22: Connection refused&lt;br /&gt;&lt;br /&gt;Mar 02 18:16:41 ssh: connect to host hapeer port 22: Connection refused&lt;br /&gt;&lt;br /&gt;Mar 02 18:16:42 ssh: connect to host hapeer port 22: Connection refused&lt;br /&gt;&lt;br /&gt;Mar 02 18:16:47 ssh: connect to host hapeer port 22: Connection timed out&lt;br /&gt;&lt;br /&gt;Mar 02 18:16:52 ssh: connect to host hapeer port 22: Connection timed out&lt;br /&gt;&lt;br /&gt;Mar 02 18:16:57 ssh: connect to host hapeer port 22: Connection timed out&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495037?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 12:12:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cc0bc2fe-26f4-4b9a-88b2-157e126ed31b</guid><dc:creator>MCSCARRASCO</dc:creator><description>&lt;p&gt;In our case XG, but I read that there are problems with XGS too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495028?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 12:03:18 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:82b2f9c9-b042-4e0d-a83c-60bed0b37acd</guid><dc:creator>Andreas Hahn</dc:creator><description>&lt;p&gt;we have XGS&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495025?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 11:59:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:828d62d9-3578-496a-b866-2751d3057987</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;has everyone here XGS machines or also XG machines? I wonder it is an issue with the co-processor.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495021?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 11:49:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f08027b2-d555-4af9-921b-af3d636eb19f</guid><dc:creator>Andreas Hahn</dc:creator><description>&lt;p&gt;Thank you for your feedback, since it affects both firewalls from the HA, we will set up a new firewall and test whether it also occurs there&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495020?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 11:45:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3ababe65-cf47-4c19-b760-b2445c7d65b5</guid><dc:creator>JasP</dc:creator><description>&lt;p&gt;We are logging a permanent serial console connection to both XGS to see if they can capture a kernel dump when the XGS fails. Waiting for a failure now.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495018?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 11:42:02 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:af3ecd84-0b4a-48c9-b273-51009e3b8805</guid><dc:creator>MCSCARRASCO</dc:creator><description>&lt;p&gt;With us there was the service, analysis and no assertive diagnosis. We are currently operating on secondary equipment that does not have the problem. when possible, we will leave the problematic equipment operating and put a monitoring system to collect logs in an attempt to find the reason for the traffic stop.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/495007?ContentTypeID=1</link><pubDate>Fri, 06 May 2022 09:43:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4acad479-a1b6-43f7-97d3-98daa36b8d7e</guid><dc:creator>Andreas Hahn</dc:creator><description>&lt;p&gt;Hello everyone, does anyone already have any feedback, with us the support still analyzes the problem...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494897?ContentTypeID=1</link><pubDate>Wed, 04 May 2022 21:02:15 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b794a1a1-9063-4b22-802a-a5e8ed86c50b</guid><dc:creator>JasP</dc:creator><description>&lt;p&gt;We have an open case with Sophos regarding this (Case# 05098782-050987). This has now been escalated all the way through global escalation specialists (GES) to Development (basically as high as it gets) - Development reference number: NC-92066&lt;/p&gt;
&lt;p&gt;We&amp;#39;ve had the issue with 18.5.2, 18.5.3 and 19.0&lt;/p&gt;
&lt;p&gt;Pair of XGS 116 in HA. Primary stops passing traffic and HA fails over to Auxillary. If you reboot the failed XGS, the HA is restored. If you don&amp;#39;t reboot the failed XGS, the new Primary will eventually fail, leaving you with no internet connectivity.&lt;/p&gt;
&lt;p&gt;I would suggest those affected open a case with Sophos and reference our case number and the development reference number. If you already have a case I would suggest you pass our case details on to your current support specialist.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494837?ContentTypeID=1</link><pubDate>Tue, 03 May 2022 21:56:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:22ce6266-e69a-49e1-ba59-0acb40cb7c10</guid><dc:creator>Andreas Hahn</dc:creator><description>&lt;p&gt;Hi everyone, we have the same problem. We have also updated from 18.5.2 to version 18.5.3. Also another update to version 19 did not help the problem persists. We have also already opened a&amp;nbsp;support ticket. (We have also dissolved the HA, this has not solved the problem either.)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494823?ContentTypeID=1</link><pubDate>Tue, 03 May 2022 15:34:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7fc78fc5-4ac9-4dd7-a872-a54a072281bf</guid><dc:creator>Peter Mastrangelo</dc:creator><description>&lt;p&gt;Update 2022-05-03&lt;/p&gt;
&lt;p&gt;We spoke too soon that the rollback to 18.5.2 appeared to correct the issue. We had the issue again today.&lt;/p&gt;
&lt;p&gt;It might be just coincidence that this issue started appearing after the 18.5.3 update. XGS was rock solid for months.&lt;/p&gt;
&lt;p&gt;We opened a support ticket.&lt;/p&gt;
&lt;p&gt;-Peter Mastrangelo&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494815?ContentTypeID=1</link><pubDate>Tue, 03 May 2022 12:12:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7e22511a-ea3c-4989-99d3-cc537bac52c5</guid><dc:creator>MCSCARRASCO</dc:creator><description>&lt;p&gt;I have the same problem in the company. Updated XG for SFOS 18.5.3 MR-3-Build408. Equipment in Active x Passive HA. Simply 1 stops traffic and only returns after restarting. We are currently operating on the secondary XG and there have been no more problems. We have an open call with Sophos to try to identify the cause.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494807?ContentTypeID=1</link><pubDate>Tue, 03 May 2022 10:29:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f9e6f0a9-d9b4-4dbd-b15e-cb9742cf3ed2</guid><dc:creator>Peter Mastrangelo</dc:creator><description>&lt;p&gt;Thank You for the answer.&lt;/p&gt;
&lt;p&gt;Unfortunately the issue happened again. We had to quickly &amp;quot;switch to passive&amp;quot; because we are a K12 school dependent on Chromebooks.&lt;/p&gt;
&lt;p&gt;I rolled back the firmware to 18.5.2 using this as a guide &lt;a href="https://support.sophos.com/support/s/article/KB-000038017?language=en_US"&gt;https://support.sophos.com/support/s/article/KB-000038017?language=en_US&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The issue has not appeared again \ yet.&lt;/p&gt;
&lt;p&gt;I did pull the logs off the device(s) and have been looking through them but haven&amp;#39;t found anything yet.&lt;/p&gt;
&lt;p&gt;We will be holding off any firmware updates 18.5.3 or possibly 19 until the end of the school year.&lt;/p&gt;
&lt;p&gt;Thank You,&lt;/p&gt;
&lt;p&gt;-Peter Mastrangelo&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XGS Stopped Working (18.5.3)</title><link>https://community.sophos.com/thread/494784?ContentTypeID=1</link><pubDate>Tue, 03 May 2022 03:50:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5f4d3d71-384a-4879-95e5-40df5a59f64b</guid><dc:creator>Excommunicado</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/peter-mastrangelo"&gt;Peter Mastrangelo&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Did you collect logs from the firewall in a broken state? Did it reboot properly after the firmware update? Did you check the uptime or any service is down?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You might find the root cause in the system or applog log files.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>