Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: v21.0 GA: Feedback and experiences

Release Post:  Sophos Firewall v21 is Now Available 

Release Notes: docs.sophos.com/.../sf_210_rn.html

Early Access EAP Thread:  Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread) 

To make the tracking of issues / feedback easier: Please post a potential Sophos Support Case ID within your initial post, so we can track your feedback/issue.   

Only XGS Hardware is supported - Not XG/SG Hardware. Sophos Home is excluded, as it uses Software, which is supported. 

Firmware update from the CM will be available after the firmware is available to all. Please refer to the standard update process.

Firmware update on Sophos firewall requires a valid support subscription (of any type - paid or trial) after the first 3 free firmware updates.

Parents
  • I've been having an issue where after a few days (3-5 days) of the firewall running, I get errors logging in. 

    Couple things I have noticed when this happens:

    • The admin portal starts showing the CAPTCHA block, even though I am local.
    • The connection to Sophos Central is broken.
    • If I attempt to login via the console (keyboard and mouse), I get the following message "/bin/csh: line 13: can't fork: Resource temporarily unavailable"
    • Unable to access SSH, Console, Admin Portal, User Portal, or VPN Portal when this happens. 

    Rebooting restores my ability to login. This did not begin to happen till I was running the EAP1 of v21. I assumed it was an EAP glitch at first. Now that I am on GA it is still happening. I do not know where to look for details of what is happening. 

    Some system info:

    • Sophos Home
    • 4 Cores (Intel i5)
    • 5 Interfaces
    • 232GB SSD drive
  • error "can't folk:.." indicates probability of low memory during that period. How was appliance's memory utilisation looks like during that period (you may check that using system graphs), also pls check if you spot any 'error' in logs (csc, syslog, postgres..)   

  • I've looked through the normal logs and found no errors. This is the home edition so I'm limited to 6GB of RAM. It does appear that in the system graph it reaches a pretty high utilization, and then stops recording the utilization. Is this possibly a memory leak? I haven't had issues like this in the past. When it's running normally my utilization is around 70%.

    Perhaps the home hardware limitation should be increased. Especially since the underlying OS is getting more features. It would make sense to me to grow it a bit. 

Reply
  • I've looked through the normal logs and found no errors. This is the home edition so I'm limited to 6GB of RAM. It does appear that in the system graph it reaches a pretty high utilization, and then stops recording the utilization. Is this possibly a memory leak? I haven't had issues like this in the past. When it's running normally my utilization is around 70%.

    Perhaps the home hardware limitation should be increased. Especially since the underlying OS is getting more features. It would make sense to me to grow it a bit. 

Children
  • Hello  ,

    This certainly looks like device hung. 

    Could you check if there is any coredump and kdump generated?

    Coredump:

    ls -lah /var/cores

    kdump:

    ls -lah /sdisk/crashkernel

    Kindly share below information or you can DM me with the firewall access ID.

    1. Number of users connected in network.
    2. ​How often device reboots or hang?
    3. CPU/Memory/Load AVG of last 48hrs or week -> you can collect it from System -> Diagnostics.
    4. Firewall acceleration status (console> system firewall-acceleration show)
    5. console>show ips-settings 
    6. Modules in used example, VPN, Web, Application, or any other features of the firewall

    Mayur Makvana
    Technical Account Manager | Global Customer Experience

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question please use the 'Verify Answer' button.

  • It appears there are some maybe in the cores directory, output below. Please let me know what file you need.

    SFVH_SO01_SFOS 21.0.0 GA-Build169# ls -lah /var/cores
    drwxrwxrwt 2 root root 12.0K Dec 31 12:00 .
    drwxr-xr-x 42 root root 4.0K Dec 31 06:44 ..
    -rw------- 1 root root 154.1K Dec 28 00:12 5c2e590e-c4da-11ef-b52b-9e527b0a7261.dmp
    -rw------- 1 root root 25.4K Dec 27 13:22 7cb539a8-c47f-11ef-8373-f95bc3281baf.dmp
    -rw------- 1 root root 28.4K Dec 27 23:03 8c61b32e-7539-48ce-74357386-14989b81.dmp
    -rw------- 1 root root 21.4K Dec 27 13:16 b38b4073-c47e-11ef-8690-db29c0956b3e.dmp
    -rw------- 1 root root 234.9M Dec 27 10:00 core.SchedulerRunner
    -rw------- 1 root root 122.6M Sep 6 18:00 core.TLSLogForwarder
    -rw------- 1 root root 42.7M Dec 27 23:11 core.fwcm-api-execut
    -rw------- 1 root root 14.9M Dec 24 14:28 core.fwcm-eventd
    -rw------- 1 root root 11.0M Dec 28 10:19 core.fwcm-heartbeatd
    -rw------- 1 root root 2.7M Dec 27 23:11 core.fwcm-updaterd
    -rw------- 1 root root 56.1M Sep 27 15:58 core.garner
    -rw------- 1 root root 174.4M Dec 30 07:48 core.osqueryd
    -rw------- 1 root root 1.0G Jul 27 04:33 core.snort
    SFVH_SO01_SFOS 21.0.0 GA-Build169# ls -lah /sdisk/crashkernel
    ls: /sdisk/crashkernel: No such file or directory

    1. Number of users connected in network.
      1. It's a home network. On average I have about around 75 devices connected to my network. 
    2. ​How often device reboots or hang?
      1. Seems to be anywhere from 3 days to 7 days before it hangs up. When it hangs up the network works as normal, except for WAF. 
    3. CPU/Memory/Load AVG of last 48hrs or week -> you can collect it from System -> Diagnostics.
    4. Firewall acceleration status (console> system firewall-acceleration show)
      1. console> system firewall-acceleration show
        Firewall Acceleration is Enabled in Configuration.
        Firewall Acceleration is Loaded.
    5. console>show ips-settings 
      1. console> show ips-settings
        -------------IPS Settings-------------
        stream on
        lowmem off
        maxsesbytes 0
        maxpkts 8
        enable_appsignatures on
        http_response_scan_limit 65535
        search_method ac-q
        sip_preproc enabled
        sip_ignore_call_channel enabled
        inspect untrusted-content
        pki-acceleration disabled
        tcp urgent-flag removed

        -------------IPS Instances------------
        IPS is running on all cores

    6. Modules in used example, VPN, Web, Application, or any other features of the firewall
      1. Web, WAF, Let's Encrypt, Application Filtering, Traffic Shaping, VPN, Site-to-Site VPN, IPS, Third Party threat feed, Sophos Central, etc. I would generally describe it as a typical home/small business setup.
  • Hello,

    Kindly share me the firewall access ID in DM.

    docs.sophos.com/.../index.html

    Mayur Makvana
    Technical Account Manager | Global Customer Experience

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question please use the 'Verify Answer' button.