Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v20.0 MR1: Feedback and experiences

Release Post:  Sophos Firewall OS v20 MR1 is Now Available 

The old V20.0 GA Post:  Sophos Firewall: v20.0 GA: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 

Important Note on EOL Sophos RED Support:

The legacy EOL RED 15, RED 15w, and RED 50 are not supported in v20 MR1. Customers using these devices should upgrade to SD-RED or a smaller XGS appliance before upgrading to MR1 to maintain connectivity. See the following article for details: Sophos RED: End-of-life of RED 15/15(w) and RED 50



Prio Change
[bearbeitet von: LuCar Toni um 4:40 PM (GMT -7) am 23 Sep 2024]
  • Hi @keobra, Please provide the clear topology of your setup. Is it policy based IPSec or RBVPN ?

  • Thanks for your feedback. We will accommodate such feedback in future implementation.

    For DHCP flooding, I have looked into the DHCP server configuration and looks no issues. Kindly open support ticket.

  • Hi  ,

    it seems you experience a knows issue that we track about wildcard domains not working in SMTP exceptions.

    Please upgrade to 20.0 MR2 when it's released, where we'll support adding IP ranges to SMTP exceptions.

    Until then, you can remove "Premium RBL Services" from the "Reject based on RBL" list.

  • Hi,

    we are using policy based VPN to that customer.


    In the customer's firewall we have lets say 10.1.0.1/24 as the real interface address for the firewall, the IPsec tunnel config on the customer's firewall is using 192.168.0.0/24 as remote network, 172.16.0.0/24 as local network (with the bultin NAT function that maps the network to 10.1.0.0/24)

    On 20GA we were able to access 10.1.0.1 via SSH and WEBADMIN from the 192.168.0.0 network, since 20MR1 only SSH is working.
    Everything we tried (advanced-firewall rules for sys-traffic, activating WEBADMIN generally from the VPN zone) had no effect.

    Packet capture is showing the incoming connection and the outbound answer but the browser says "connection refused".
    In Local ACL the network 192.168.0.0/24 is allowed from VPN zone to ANY for WEBADMIN, SSH, PING,...

    Edit: system ipsec_route add net 192.168.0.0/24 brings an error as soon as press TAB.

    console> system ipsec_route add net 192.168.0.0/24
    % Error: Unknown Parameter '192.168.0.0/24'
    

    Edit2: ok whoever thought 192.168.0.0/255.255.255.0 is good notation should be ashamed... but that also doesn't solve it.
    Routing precedence is sdwan, static, vpn if that makes a difference.

    Regards,

    Kevin

    Sophos CE/CA (XG, UTM, Central Endpoint)
    Gold Partner

  • Thanks Janos for the reply and letting me know about the known issue with wildcards, we have disabled the Premium RBL with Spamcop and will wait for MR2 for a better resolution.

    In the meantime, is there any replacement RBL besides Spamcop that you can recommend that works with SFOS?

  • Found a small minor bug in SFOS 20.0.1 MR-1-Build342

    Bandwidth utilization of the interfaces is not shown.
    (tested under software and Hyper-V VM)

  • Hi  Thanks for the details;  let me put a drawing so that what you are stating vs. what is understood to us is same.

    ---172.16.0.0/24 ----SFOS1<ip1> --------------policy based ipsec tunnel-------<ip2>SFOS2------192.168.0.0/24----client

    Are you accessing SFOS1 on <ip1> from client's browser and expect to see the UI of SFOS1 accessible over IPsec tunnel? I am assuming 'customer firewall' is referred to SFOS1 and your firewall is SFOS2?

    Regarding you NAT description, it is still not clear; When you say "with the bultin NAT function that maps the network to 10.1.0.0/24" - can you please elaborate on this? Are you doing NAT on UI of IPSec tunnel config? or in the cish cli ? or in the "Rules and Policies --> NAT rule" ? is NAT being done on both SFOS1 and SFOS2? we need details on this so that we will attempt the exact setup/config  internally.

    Is <ip1> configured on SFOS1 from 10.1.0.0/24, which is used to host the tunnel?

    Let us know if you are fine to have a call over zoom to go over your configs/setup. You can DM me, we can reach out to you for further triage.

  • Does the filtering in Email > Relay settings > Host based relay > "Allow relay from hosts/networks" work for you? I have this field blank and ANY in the "Block relay from hosts/networks" field. Yet SMTP Realy works for me from any source. Am I doing something wrong? 

  • Are you using mta mode?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Is this KBytes or Kbits?

    Recently my wan link was upgraded to 1000/50. I have experimented with the values in the fields and even when set at 1000Gb/s I only get around 550-550 download.

    From past experiments the XG115w could only download at about 700-750 max occasionally. The RSP acknowledges that maximum download is usually around 950Mb/s due to overhead limitations in the NBN.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.