Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v20.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v20 is Now Available  

The EAP Post:  Sophos Firewall: v20.0 EAP1: Feedback and experiences  

The old V19.5 MR3 Post:  Sophos Firewall: v19.5 MR3: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 



This thread was automatically locked due to age.
  • Hi Hans,

    Core Agent 2023.2 is being rolled out in a phased manner.

    Thanks,
    Vamsee

  • Could it be possible that IPv6 prefix delegation is not working correctly in combination with PPPoE over a VLAN?
    Situation for my provider is that I have a fiber connection with an ONT converting the fiber to a RJ45 cable. On that cable the signal has internet on VLAN6 and television on VLAN4.

    On VLAN6 I need to do PPPoE to connect to the internet which works and gets me an IPv4 address from my provider.

    On this connection my provider is also handing out a /48 IPv6 subnet which others have had success in using PD on OPNsense and pfsense firewalls, however in SFOS v20 I don't seem to get it to work.

    Below screenshots from my current setup, maybe someone sees a glitch in my settings (or it might be something in v20). As you can see in the first picture I'm only getting an IPv4 address.

    I also tried static v6 and entered an address that they have reserved for me, but that didn't work either, it should be possible using DHCP.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Hello apijnappels,

    At first glance, I don't see anything wrong in the configuration.

    Let me connect with you via PM to get access details and follow-up questions.

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

  • The same issue happens with me over two PPPoE connections.

    I've reported this on the v20 EAP, but the answer I got was "DHCPv6-PD not supported if the main connection (v4) is PPPoE."


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • Access id generated and sent through PM. Would be really great if this is possible despite message from    saying he reported the same issue in EAP.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • I've v20 installed and was hapy, to found the first 50% of an idea, that i've posted in v18/19 (not sure witch version) Smiley

    • Amount of links per Service / Host ( Objects is now availible = 50% of my idea.

     
    What is missing to find my idea 100% ? 

    • Under the heading "Usage" there is a refresh button, there is still a buttin missing, which can change the sorting order, i.e. sort the objects linking from 0 upwards, so that you can see all unused / unlinked objects and then delete them after checking without having to scroll through the entire object list. 

     

    I hope, this addon can be set on the Ideas listing for V20 Thinking

    Thx forwarsd

    ChrisGER

  • You can click on usage and change the sorting: 

    __________________________________________________________________________________________________________________

  •   I understand you may not have received many requests for it, but as I have stated to the Sophos team over and over again, why implement a new feature that only partly works? If the feature works for a physical interface, there is no reason it shouldn't work on a LAG as well. That's just stupid for any feature. As more networks need higher availability, LAG will be used more and more. Make the features work on both.

  • Couldn't agree more. Sophos conveniently took down the ideas site where actual end users were voting on features. LE was at the top of the list, but they still won't make it happen. I don't understand. We need a new version of the ideas site that Sophos actually listens to.