Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.5 GA: Feedback and experiences

Release Post:  Sophos Firewall v19.5 is Now Available 

Old v19.0 MR1 thread:  Sophos Firewall: v19.0 MR1: Feedback and experiences 

EAP Sub thread:  SFOS v19.5 Early Access Program (Read Only) 

EAP 19.5 Thread:  Sophos Firewall: v19.5 EAP1: Feedback and experiences 



This thread was automatically locked due to age.
  • I have updated 2 test firewalls to 19.5 today. Both have a tunnel to an XG with 19.0.1 and dynamic routing with OSPF. The first firewall has an IPSec tunnel, here the tunnel stood after the update, the OSPF negotiation basically worked (no error messages in the log), however the firewall did not distribute its own route, so the site was not reachable. Reboot and reconfigure OSPF did not help. After a rollback to 19.0.1 the OSPF worked again.
    The second firewall has a RED tunnel to the central office, there are no problems with OSPF there.
    Are there any known issues with SFOS 19.5, IPSec and OSPF?

    Ben

    If a post solves your question please use the 'Verify Answer' button.

  • Hi      Dev team would like to investigate why this is not working in your setup.Can you share the support access for your device/s in  Private message to me? Meanwhile some quick info on this  will help team to start with 1. config from /conf/routing/ 2. Logs: /log/csc.log , /log/ospfd.log , /log/zebra.log 3. ifconfig output 4. complete backup of the device config if available . Also If possible please provide device support access id for to login and check more. -Shrikant

  • Hi, I send you the access ID via PM. -Ben

    If a post solves your question please use the 'Verify Answer' button.

  • We had some downtime so we jumped back to 19.5 if you want to jump in firsthand and see the issues.

  • We had some downtime at the plant, so we jumped back to 19.5 If support wants to jump in first hand and see the issues. Hit me up via IM

  •   
    Hey Guys,  and I re-upgraded to 19.5 so we could do some testing and appy the above command. When we have all 4 tunnels up, the intended subnet doesn't get advertised to the expected peers. So we did the "no bgp network import-check", but it didn't resolve the issue. When we down one of the tunnels, I can see that the subnets then get advertised to the other tunnel that shares a peer with the tunnel that was shut down.

    Any additional tests we could perform?

  • Hello,

    i installed yesterday the firmware. After that i was faced with following issue:

    In SSL Inspection i habve 3 rules in the following order:

    1. Exclusions by website

    2. a rule with no decryption enabled from LAN with the Range of Smartphones to the internet

    3. a rule with decryption from LAN any devices to the internet

    Until yesterday everything worked perfectly. But now every device uses rule 3.  It seems that the order of the rules no longer matters. i had to define in rule 3 also a range with devices for decryption.

    I don't think that should be the case, right?

    Greets

    Andreas

  • Hi,

    this morning I was investigating the settings on both of my XGs and found that the Anti-virus and the anti-spam had not updated since the 19th. One is set for 4 hours and the other for 15 minutes.

    I initiated a manual update and both download anti-virus patterns dated the 20th November.

    Ian

    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    this morning I was investigating the settings on both of my XGs and found that the Anti-virus and the anti-spam had not updated since the 19th. One is set for 4 hours and the other for 15 minutes.

    I initiated a manual update and both download anti-virus patterns dated the 20th November.

    Ian

    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi folks,

    further update. The XG with the 15 minute update schedule is not showing any new updates since the manual update at approx 1030 20/11 and the IPS data base has not updated since the 17th Nov 2022.

    Ian

    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.