Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v20.0 MR1: Feedback and experiences

Release Post:  Sophos Firewall OS v20 MR1 is Now Available 

The old V20.0 GA Post:  Sophos Firewall: v20.0 GA: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 

Important Note on EOL Sophos RED Support:

The legacy EOL RED 15, RED 15w, and RED 50 are not supported in v20 MR1. Customers using these devices should upgrade to SD-RED or a smaller XGS appliance before upgrading to MR1 to maintain connectivity. See the following article for details: Sophos RED: End-of-life of RED 15/15(w) and RED 50



Prio Change
[bearbeitet von: LuCar Toni um 4:40 PM (GMT -7) am 23 Sep 2024]
Parents
  • Issue with one IPSec tunnel after update to SFOS 20-MR1

    We have an issue with one IPSec tunnel from a site office to the HQ Firewall. First, we updated the firewall in the site office from SFOS 20 to MR1. After the update the IPSec won't come up. Reboot of firewall and recreating the tunnel does not help.

    We updated around 80 firewalls, they all establish a tunnel to the HQ firewall. All IPSec tunnels are up, except one. As workaround on the firewall that will not establish the IPSec tunnel, we build an RED tunnel to the HQ firewall which works very well. 

    In the last step we updated the HQ firewall from SFOS 20 to MR1. But it changes nothing: All tunnels are up except one tunnel. 

    I already opened a ticket for this issue. Has anybody the same issue with IPSec after the update?

    If a post solves your question please use the 'Verify Answer' button.

  • Hi - I am from the IPsec team and we have not seen any one reporting such issue after upgrade to v20.0MR1. Either, DM us the access-id of the Site office device or provide the strongswan logs from the BO and HO nodes. WE will take a look at the logs and come back after going through them,

Reply Children