Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v20.0 MR1: Feedback and experiences

Release Post:  Sophos Firewall OS v20 MR1 is Now Available 

The old V20.0 GA Post:  Sophos Firewall: v20.0 GA: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 

Important Note on EOL Sophos RED Support:

The legacy EOL RED 15, RED 15w, and RED 50 are not supported in v20 MR1. Customers using these devices should upgrade to SD-RED or a smaller XGS appliance before upgrading to MR1 to maintain connectivity. See the following article for details: Sophos RED: End-of-life of RED 15/15(w) and RED 50



Prio Change
[bearbeitet von: LuCar Toni um 4:40 PM (GMT -7) am 23 Sep 2024]
  • Hi  ,

    DMed you the access ID and the log. I was using a .scx file - I exported a new config after the update and also updated SCC to 2.3, issue still exist.

    With the .pro file SCC can't fetch the vpn portal - VPN Portal service is enabled on WAN in ACL.

    _______________________________________________________

    Sophos SG 210 with Sophos XG Home - 20.0 MR 1

    If a post solves your question please use the 'Verify Answer' button.

  • Central SSO will use the language of Central itself.
    You see this in the URL while using Central SSO.

    If Central is in English, you will have the firewall webadmin in English, using German for example, translate the webadmin in German.

    Do you think, there will be a use case, where customer have a English Central, but want to use a German SFOS webadmin?

    __________________________________________________________________________________________________________________

  • Hi  ,

    Please try to check the radius server group name attribute. It looks like the group name is configured instead of the group name attribute. This can be create an issue during user-group membership update and user login is rejected because of missing required policy attachment.

    Thanks

  • Thanks for   for mentioning NC-117690 fixed on the other posting here.

    • Enhancement: Boot options: DHCP now supports boot server and boot file options in the DHCP header. You can also continue to send the parameters through specific DHCP options to provision network devices.
  • Central SSO will use the language of Central itself.

    Thats fine!

    Do you think, there will be a use case, where customer have a English Central, but want to use a German SFOS webadmin?

    Not really, but the other way around. I usually always want to have a FIrewall UI in english. I might switch Central to German, etc.

  • Thank you   for reporting this and for your assistance.

    We have identified the root cause of the issue and will release a hotfix for it ASAP.

    I'll update this thread when the hotfix is released and you can move to 20.0 MR1 again.

  • I had the opposite problem: the OpenVPN client (on a Mac) had to be run with Legacy Security because my XGS was insisting on compression on the down-link (even though the box was not checked).

    UPDATE: Tested it out, and I'm now able to use OpenVPN Connect with it's Preferred (advanced) security setting and it works. So compression is not done by the v20.0 MR1 update. Great!

  • The hotfix is released, the IMAP proxy should work again on 20.0 MR1.

    Please let us know when you can confirm this.

  • Hii Janos,

    I have rolled forward to v20.0.1 MR-1 and mail download is working. CPU is running higher than normal, but usually takes a couple of hours to settle down after an upgrade.

    I can't find any sign of the hot fix being applied eg no record in either logviewer - admin or system.

    Regarding that other mail issue II highlighted in the DM, I will send the support team a new access ID later today. There no sign of SASI scanning the emails still.

    Thank you for the prompt fix.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian, 

    Glad to hear your issue is resolved. Thank you so much for flagging this issue to us, and helping us fix it. 

    If you look in /log/u2d.log, you should see entries like this: 

    2024-05-17 15:17:28Z dr_dload_checker: Starting download for file sfsysupdate_NC-135882_2.tar.gz.sig
    2024-05-17 15:18:28Z dr_dload_checker: Download completed for file sfsysupdate_NC-135882_2.tar.gz.sig
    2024-05-17 15:18:28Z dr_dload_checker: Download for file sfsysupdate_NC-135882_2.tar.gz.sig passed integrity and sig checks
    Fri May 17 08:18:28 2024 [Hotfix]: Affected version '20.0.1.342' found
    Fri May 17 08:18:28 2024 [Hotfix]: Stopping services
    Fri May 17 08:18:28 2024 [Hotfix]: Backing up original files
    Fri May 17 08:18:28 2024 [Hotfix]: Copying files
    Fri May 17 08:18:28 2024 [Hotfix]: Restarting services
    Fri May 17 08:18:28 2024 [Hotfix]: Start service: warren

    This shows the hotfix 'sfsysupdate_NC-135882_2.tar.gz.sig' being downloaded & installed. 

    Note: You can now download the debug logs from Admin UI under Diagnostics -> Tools -> Troubleshooting logs, without having to go into the advanced console. This is a new feature in MR1.