Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.5 MR1: Feedback and experiences

Release Post:   Sophos Firewall OS v19.5 MR1 is Now Available 

The old V19.5 GA Thread:  Sophos Firewall: v19.5 GA: Feedback and experiences 



Removed Prio.
[gesperrt von: LuCar Toni um 11:37 AM (GMT -7) am 9 May 2023]
Parents
  • This has been a very bad experience for us. 

    Running 2 XGS21000 in HA mode. 

    Since upgrading connectivity to websites is slow, sometimes hangs completely. Some apps will get disconnected after a few minutes of use. This is consistent so has made those apps useless, for example my General Manager has stopped using Sirius XM radio on his desktop because it will not stay connected. When these problems are happening we see many "invalid packet" in the log file for that client and service. This indicates a problem with nf_conntrack but the only thing support has been able to do for the past few weeks is try adjusting the tcp-est-idle-timeout but the timeouts are already happening much sooner than the timeout value. We will probably roll back soon but if we do that how will we know when it's safe to upgrade again? It is a problem. 

  • Hello there,

    I am sorry to hear about your bad experience.

    Can you share the Case ID you have open with Support?

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply Children