Sophos Firewall: v19.0 MR1: Feedback and experiences

Parents
  • I have a problem with firewall rules. Since I upgraded from 19.0 GA to 19.0 MR1, my WIFI rule is not working anymore, nothing is let through. No ping, no TCP connection from LAN zone to WIFI zone:

    As you can see, 0 bytes sent/received. When I switch back to 19.0 GA it all works again and counters go up. I have no explanation why this is happening, any idea where to look for in the logs?

    Edit: Same seems to be the case for Rule #11 SMTP.

  • Why do you use a rule without Logging? 

    Check the packet capture - There you should see the used Firewall/NAT Rule. 

    Maybe another rule picks up the traffic. Automatic VPN Rule is something, which could potentially cause issues. 

    __________________________________________________________________________________________________________________

  • Thx I will see what turned on logging will bring.

    However there was a "breaking change" in 19.0 MR1...

  • Ok now I moved those 2 rules to the top:

    And with MR1 there is still no traffic in the "LAN to WIFI" rule. I even deleted the WIFI rule and recreated it. Still the same.

    The log viewer shows nothing for that destination IP 10.0.2.14.

    Packet capture showed violation by "Firewall".

    Rule 0 is the default drop rule, but how can it be that this is now taken, when my rule should cover the connection?

    So it seems there is definitely something broken with the WIFI connections (all others seem to work), as it works with 19.0 GA without a problem.

Reply
  • Ok now I moved those 2 rules to the top:

    And with MR1 there is still no traffic in the "LAN to WIFI" rule. I even deleted the WIFI rule and recreated it. Still the same.

    The log viewer shows nothing for that destination IP 10.0.2.14.

    Packet capture showed violation by "Firewall".

    Rule 0 is the default drop rule, but how can it be that this is now taken, when my rule should cover the connection?

    So it seems there is definitely something broken with the WIFI connections (all others seem to work), as it works with 19.0 GA without a problem.

Children