Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v21.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v21 is Now Available 

Release Notes: docs.sophos.com/.../sf_210_rn.html

Early Access EAP Thread:  Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread) 

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue.   

Only XGS Hardware is supported - Not XG/SG Hardware. Sophos Home is excluded, as it uses Software, which is supported. 

Firmware update from the CM will be available after the firmware is available to all. Please refer to the standard update process.

Firmware update on Sophos firewall requires a valid support subscription (of any type - paid or trial) after the first 3 free firmware updates.

Parents
  • Why is it not possible to download the private Key File for the LE generated certificates?

    Some of our Customers protect Web Servers that use Certificate Pinning(eg. Exchange Server with Extended Protection). 

    We now have to download the files via SSH or API.

    I'm not complaining that it is accessible via the API, that's quite nice for automation purposes. But we did not have had time to write scripts that automagically extract the pem files, create pk12 and import them to IIS, yet. Until then, we have to do it manually. It would have been easier to extract the Certs via the Web admin GUI.

Reply
  • Why is it not possible to download the private Key File for the LE generated certificates?

    Some of our Customers protect Web Servers that use Certificate Pinning(eg. Exchange Server with Extended Protection). 

    We now have to download the files via SSH or API.

    I'm not complaining that it is accessible via the API, that's quite nice for automation purposes. But we did not have had time to write scripts that automagically extract the pem files, create pk12 and import them to IIS, yet. Until then, we have to do it manually. It would have been easier to extract the Certs via the Web admin GUI.

Children
No Data