Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v21.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v21 is Now Available 

Release Notes: docs.sophos.com/.../sf_210_rn.html

Early Access EAP Thread:  Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread) 

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue.   

Only XGS Hardware is supported - Not XG/SG Hardware. Sophos Home is excluded, as it uses Software, which is supported. 

Firmware update from the CM will be available after the firmware is available to all. Please refer to the standard update process.

Firmware update on Sophos firewall requires a valid support subscription (of any type - paid or trial) after the first 3 free firmware updates.

Parents
  • we have several v20 XGS Firewalls connected via IPSec via IKEv1 to a Sophos UTM. This is very stable.

    after we upgraded the first of these XGS to v21 GA the tunnel is unstable ad disconnects/reconnects multiple times per day with timeout while all other XGS VPN to UTM stay online fine.

    VPN-1 - IKE message retransmission timed out. (Remote: WAN-IP-Of-UTM)

    This is happening roughly every 1:30 or 1:45 hours.

    XGS is VPN initiator and Key lifetime is 43200 (12h)

  • Hi @LHerzog,

    Is it possible to provide the access-id of XGS and UTM in a DM, will check the configs and behaviour. Please mention one of the problematic tunnel name.

    The logviewer shows that child SA rekey message from XGS to UTM probably are timing out. Does it correlate with the Phase2 (child SA) rekey timer configured on XGS? Although it is stable on v20, please check Phase1/Phase2 timers on XGS (Initiator) are lesser than the Phase1/Phase2 timers of UTM (Responder) of any given tunnel.

    We have one limitation and workaround as per this from v20.MR1 or V21, but this is with IKEv2

    https://support.sophos.com/support/s/article/KBA-000009744?language=en_US

Reply Children