Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v20.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v20 is Now Available  

The EAP Post:  Sophos Firewall: v20.0 EAP1: Feedback and experiences  

The old V19.5 MR3 Post:  Sophos Firewall: v19.5 MR3: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 



This thread was automatically locked due to age.
  • The same issue happens with me over two PPPoE connections.

    I've reported this on the v20 EAP, but the answer I got was "DHCPv6-PD not supported if the main connection (v4) is PPPoE."


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • Hello apijnappels,

    At first glance, I don't see anything wrong in the configuration.

    Let me connect with you via PM to get access details and follow-up questions.

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

  • Could it be possible that IPv6 prefix delegation is not working correctly in combination with PPPoE over a VLAN?
    Situation for my provider is that I have a fiber connection with an ONT converting the fiber to a RJ45 cable. On that cable the signal has internet on VLAN6 and television on VLAN4.

    On VLAN6 I need to do PPPoE to connect to the internet which works and gets me an IPv4 address from my provider.

    On this connection my provider is also handing out a /48 IPv6 subnet which others have had success in using PD on OPNsense and pfsense firewalls, however in SFOS v20 I don't seem to get it to work.

    Below screenshots from my current setup, maybe someone sees a glitch in my settings (or it might be something in v20). As you can see in the first picture I'm only getting an IPv4 address.

    I also tried static v6 and entered an address that they have reserved for me, but that didn't work either, it should be possible using DHCP.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Hi Hans,

    Core Agent 2023.2 is being rolled out in a phased manner.

    Thanks,
    Vamsee

  • Hi Vamsee,

    thanks a lot for your prompt reply!

    Can you specify which Endpoint version it needs to get the changes that you mention?

    All our Windows clients currently run

    Core Agent 2023.1.3.6
    Sophos Intercept X 2023.1.1.7

    Is there anything newer out yet?

    Best,

    Hans

  • Hi Hans,

    Thanks for your post.

    To avoid false missing heartbeat alerts due to modern standby, changes are needed on both SFOS and Endpoint.
    SFOS 20.0 has these changes. Similarly Windows Endpoint also made the necessary changes and are available to customers with latest version, which is being rolled out.
    MacOS Endpoint changes are in pipeline and will be available in future.

    Hope this answers your query.

    Thanks,
    Vamsee

  • In the release notes it was mentioned, that Heartbeat false positives have been reduced: "Synchronized Security has also been enhanced with added scalability and reduced false missing heartbeats for devices that are in a sleep or hibernate state."

    After upgrading to SFOS 20 we still see the same amount of false positives concerning "missing hearbeat" alerts as with v19.x before.

    Can anyone confirm that in v20 anything has changed here to the better and what one can do to improve the situation? Our workaround currently is to avoid S0 (modern standby) as much as possible, but this is not a very convenient solution and is not applicable to every device (MacOS for example).

    Thanks for any comments.

    Hans

  • Hi  , I have shared the meeting invite in PM

  • I can't reply to your PM but the time you suggested it ok for me