Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v20.0 MR2: Feedback and experiences

Release Post:  Sophos Firewall OS v20 MR2 is Now Available    

The old V20.0 MR1 Post:  Sophos Firewall: v20.0 MR1: Feedback and experiences  

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue. 

Release Notes:  https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_200_rn.html 

Important Note on EOL Sophos RED Support:

The legacy EOL RED 15, RED 15w, and RED 50 are not supported in v20 MR1. Customers using these devices should upgrade to SD-RED or a smaller XGS appliance before upgrading to MR1 to maintain connectivity. See the following article for details: Sophos RED: End-of-life of RED 15/15(w) and RED 50



This thread was automatically locked due to age.

Top Replies

  • Just to be careful about GDPR issues here. 
    using the same firewall for multiple customers can lead to compliance problems. 
    as you share data and the device could potentially have data from the previous customer, this is always a situation to be mindful about. 

    We also recommend to look into a HA deployment for customer having a certain need of availability 

    __________________________________________________________________________________________________________________

  • We rolled back to MR1 after 1 day. Experiencing massive voip problems (very often we could not be heard on the other end either at the beginning of the call or after some time); no changes in configuration; since we had not experienced  any problems before, we rolled back and after that.. no more problems.

    Best regards

    Michael

  • Hello Michael Krüger

    Could you please share appliance access ID over PM?

    Let me ask few questions so I can understand the problem better:

    - Do you use SIP helpers in SFOS?

    - Are you using STUN support in VOIP clients?

    - When voip problem occurred, did you notice any traffic in drop-packet-capture or Invalid traffic in firewall logging?

    - Did you notice any WAN link gateway flapping during voip problem?

    - Could you please share some ruff timeline when problem occurred? It will help to analyze log events during that time frame.

    - Topology details of voip clients and voip server would be helpful.

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

  • Hi Sanket,

    thanks for your instant reply.

    - No SIP helpers

    - All VOIP Clients internal in same subnet as PBX, only SIP-trunk traffic going through XGS to provider 

    - Did not have time to analyze and in the end rolled back

    - No WAN link problems

    - all other services without problems

    - will provide you with further details via PM

    Best regards

    Michael

  • Thank you for the information,  .

    We will dig it further once access is available.

    BTW, you don't need to switch back to MR2, we will try to gather as much information as possible from MR1 version only so you won't face any interruption.

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

  • Using Central to perform upgrades.

    i have tried using Central on two different devices to perform the upgrade and nothing happened.

    On the software version I had to login locally to perform the upgrade. So what are the steps I am missing to perform an upgrade through Central?

    ian

    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • What does „nothing happened“ mean? MR2 showed up in Central for upgrade and you scheduled there? 
    Or opening WebAdmin through central and uploading firmware-file there failed? - if that‘s that’s the case I think  said before that‘s not recommended. Manual upload should use direct WebAdmin access.

  • This happened because v20 MR2 is still NOT available to all, please refer to the 3 phases of firmware release, here: The 3 phases of Sophos Firewall firmware release

    v20 MR2 firmware release will follow standard update process. You can manually download SFOS v20 MR2 from Sophos Central and update anytime. Otherwise, it will be rolled out to all connected devices over the coming weeks. A notification will appear on your local device or Sophos Central management console when the update is available, allowing you to schedule the update at your convenience.

  • Hello  ,

    Thank you for sharing appliance access. We are looking into the available logs of 23rd and 24th July.

    I am trying to connect you via PM but it's throwing me following error.

    "You cannot currently message this user, either you do not have permission or the user is not accepting messages."

    Could you please allow me to send message to you?

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall