Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.5 MR2: Feedback and experiences

Release Post:   Sophos Firewall OS v19.5 MR2 is Now Available  

The old V19.5 MR1 Post: Sophos Firewall: v19.5 MR1: Feedback and experiences 

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 



This thread was automatically locked due to age.
Parents
  • Hi

    I upgraded our XG135 from 19.5.1 MR-1-Build278 to 19.5.2 MR-2-Build624 and the SSL/TLS Inspection broke completely.

    1. After the upgrade every domain/url that was not specifically excluded in URL Groups - Local TLS exclusion list, was erroring and would time out

    2. All of the domains that subsequently errored in Log Viewer - SSL/TLS Inspection, would also be "uncategorized" and all under SSL/TLS Rule - 0

    3. This behaviour would also happen in Firewall rules where "Scan HTTP and decrypted HTTPS" was not selected

    4. Turning Off SSL/TLS Inspection would have no effect

    5. Directly rolling back to 19.5.1 MR-1-Build278 would have no resolve

    6. Restoring a backup taken just before the upgrade would also not resolve the broken SSL/TLS inspection

    7. Last resort was to reset the XG to factory default on 19.5.1 MR-1-Build278, and then restoring the last backup, and this fixed the broken SSL/TLS created by upgrading to 19.5.2 MR-2-Build624.

    8. Our one RED device also refused to connect until after the factory reset and backup restore

    Needless to say I am not upgrading to 19.5.2 MR2 unless there is a specific reason or fix for this issue

Reply
  • Hi

    I upgraded our XG135 from 19.5.1 MR-1-Build278 to 19.5.2 MR-2-Build624 and the SSL/TLS Inspection broke completely.

    1. After the upgrade every domain/url that was not specifically excluded in URL Groups - Local TLS exclusion list, was erroring and would time out

    2. All of the domains that subsequently errored in Log Viewer - SSL/TLS Inspection, would also be "uncategorized" and all under SSL/TLS Rule - 0

    3. This behaviour would also happen in Firewall rules where "Scan HTTP and decrypted HTTPS" was not selected

    4. Turning Off SSL/TLS Inspection would have no effect

    5. Directly rolling back to 19.5.1 MR-1-Build278 would have no resolve

    6. Restoring a backup taken just before the upgrade would also not resolve the broken SSL/TLS inspection

    7. Last resort was to reset the XG to factory default on 19.5.1 MR-1-Build278, and then restoring the last backup, and this fixed the broken SSL/TLS created by upgrading to 19.5.2 MR-2-Build624.

    8. Our one RED device also refused to connect until after the factory reset and backup restore

    Needless to say I am not upgrading to 19.5.2 MR2 unless there is a specific reason or fix for this issue

Children