For those that upgraded, any risks of functionality breaking?
One concern I have is whether VPN users certificates will change and need re-enrollment?
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
For those that upgraded, any risks of functionality breaking?
One concern I have is whether VPN users certificates will change and need re-enrollment?
We did an upgrade from 18.5 MR3 to 19.0 last week. Nothing broke, all Client-VPN and site-to-site VPN are working as before.
I would recommend doing a configuration backup of the firewall system before any upgrade, though.
Mit freundlichem Gruß, best regards from Germany,
Philipp Rusch
New Vision GmbH, Germany
Sophos Silver-Partner
If a post solves your question please use the 'Verify Answer' button.
If you're upgrading from 18.5.2 MR2 and performing antispam filtering be aware that the antispam engine has been upgraded to SASI and the detection rates are truly abysmal. Wait for 19.0.1 MR1 and hope Sophos have fixed the detection rates. (NC-90702) is supposedly the fix for this.
I have heard from issues with SFP+ modules in combination of LACP trunks (HP and Cisco)
Probably effects DAC and Fiber Cables (with original transceivers). I was told that 10 GBit Copper Cables are NOT effected.
Did anybody notice problems with IPSec Tunnels (Site-by-Site; Tunnel Mode)
check for Auto Negotiation. Set it, if not set.
__________________________________________________________________________________________________________________
Auto Negotiation is set.
LACP link with Firmware 18.5 MR3 works well.
You could try to disable it and check, if the Links are online or not.
__________________________________________________________________________________________________________________