Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v20.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v20 is Now Available  

The EAP Post:  Sophos Firewall: v20.0 EAP1: Feedback and experiences  

The old V19.5 MR3 Post:  Sophos Firewall: v19.5 MR3: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 



This thread was automatically locked due to age.
  • HI Paul, 

    We require access ID for further investigation - is that possible for you to share that via PM ?

    Saurabh Pandya,

    Sr Manager, Software Development, Sophos Firewall

  • Same problem here. Firewalls registered before BST are not visible in the Firewall Licenses in Sophos Central



    In the same time Sophos Central Partner Dashboard returns HTTP ERROR 500



     Support cases 07092095 and 07092581

  • Hi Paul

    I've checked the SMTP logs on your firewall.

    Apparently, the external SMTP server that is configured to handle notifications under "Administration > Notification settins" rejects emails larger than 2MB.

    The size of the backup emails exceeded 2MB after the upgrade, hence they get rejected.

    Please check the configuration of your external SMTP server and increase the size limit.

    Thank you,

    Janos

  • Hello Janos

    Thank you, everything working again!

    I have increased the size limit for emails on my external SMTP server.

    Thank you for your help!  Very happy home user!  Very happy with support response!  Just sorry it was all meBlush

    Regards

    Paul

  • Hi BhruguPatel,

    thank you for the update. I have been reviewing the logviewer traffic in CM to see if that report provides a different answer, but no. I am confused because the issue then raises concerns about the accuracy of XG logviewer reports when trying to debug firewall rules and NAT settings. The CM report does not show any traffic being passed by any devices on the 3 LANs directly to the NTP server using either IP4 or IPv6 addresses. The NTP server is setup in the DHCP server options to point at the local NTP server.

    Ian

    Fixed the missing items from logviewer, a missing configuration in the firewall rule.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hello Marek,

    Thank you for the Case IDs; I have left a note on both of them and we’ll monitor the progress. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi Ian Thanks for feedback

    regarding 1/ , the fixes are on the way for next MR for v20 and tracked via internal tickets NC-123230, NC-123249

  • Hi Sanket Shah,

    thank you for your assistance. My apologies for the delayed response, I did not see your request until today.

    The delegated process does not allow for management of address allocation and from past experience your devices are assigned two addresses from within the delegated range. Controlling access to the internet then becomes an issue.

    The IPv6 lease table only shows dynamic leases not static leases, I am expecting the IPv6 lease table to look very similar to the IP4 table to assist with network management.

    Also I was hoping that the IPv6 lease table fields might be expandable so you can see all the field, not just part of it.

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Will FQDN support for SD-WAN probes be available over a v20 MR release?


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • As soon as I upgraded on firewall, IPSEC routing is broken. FW that was upgraded says packets sent according to packet capture but never arriving at the other side, which is still on 19.5.3