Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.5 MR3: Feedback and experiences

Release Post:  Sophos Firewall OS v19.5 MR3 is Now Available  

The old V19.5 MR2 Post:  Sophos Firewall: v19.5 MR2: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes: https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=xg&versionID=19.5 



This thread was automatically locked due to age.
  • Hi,

    Your local (inbuilt) AP is offline right now - however it isn't reflect status to UI due to same issue (we're counting this to fix in same JIRA  NC-123230. 

  • Hi,

    the local AP is still active, I have removed the APX120 for the moment, it is used for testing.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian, 

    In SFOS local APs goes inactive on UI (i.e. SFOS shows "-" in status column) - only when 

    Entire "Wireless Protection" is turned OFF, this disables LocalWiFi0 (Inbuilt AP) as well as other AP/APX.

    As mentioned it require device reboot to reflect on UI.

    Hope this answers what you're facing.

  • It’s not related to MR3 or upgrade, we have captured the logs for further investigation.

    It looks like while SSLVPN service was coming up it got timed out and terminated by the parent service, but it returned error for termination request and hence it got stuck. Historically, we have seen a similar issue once earlier on another version by one of the customers. 

    Appliance reboot has resolved the problem for now.

  • Yes, thank you very much  !

  • Hi,

    Would you please share support access ID in DM?

    We have similar observation once locally so wanted to confirm whether it's similar or not.

  • Done.

    Isn

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Today I thought: so lets update my cluster (xg550) from 19.0.2 to 19.5.3.
    So I uploaded the file and clicked "upload and boot" as always when i am doing an update.

    The first node was updated successfully and it came back really quick and the modules are working.

    The second node went offline and never came back.
    After waiting around 30 minutes i had a look at my KVM and saw that the node is stuck on "booting 19.5.3".

    After 20 minutes i decided to completely power off this machine and repower it.
    Same problem. Not booting.

    I said to me "everyone advises to reimage in this case". so i disabled ha - what could go wrong.

    But no. The license exited the game and is lost now. I have tried to transfer it to now standalone host. On mysophos it says the standalone serial number is holding the license. But when i sync the license on webadmin, only base license is active. All other modules are with no subscription. So functionality is broken.

    Then i created a case and called sophos instantly. Now i am in the 5. teamqueue waiting the problem to be solved. I am on the line for 1hour 31 minutes now and no ending is on the horizont. The license seems to be blocked by the old device.

    GG. The XG licensing service is a very big problem SOPHOS. Since first version of XG I only have trouble with this...

  • Can you send me the Serialnumbers per PM? 

    __________________________________________________________________________________________________________________

  • Ok licensing team got this. Now i was able to sync the license and it seems license sync is working again.
    It took 1hour and 43 minutes on the telephone and 5 different support teams to fix this...

    I reimaged the second node already and will try to enable HA on monday.