Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall not being discovered in Central Firewall Manager

I have a XG105 firewall that does not appear in Sophos Central Firewall Manager and the Discover at top of page does not show the firewall.

I have the settings configured on the xg firewall / Administration-Central Management as instructed by Sophos documentation.

I have shared the firewall My Account-Network Protection-View Devices and also accepted the Management of firewall

I also have the latest firmware: SFOS 16.05.6

I have changed the xg device settings from Central will push to Firewall will fetch but that does not work either.

Does anyone have a suggestion?Thanks



This thread was automatically locked due to age.
Parents
  • Hi John,

    Please email me your XG105 serial number and your partner account username, so i will check the issue and get back to you.

    Also provide XG device Central Management page screenshot.

    Ravi

     

  • Hi John,

    Thank you for providing the requested detail. I have checked the issue and found issue as bug.

    Reference id: NCCC-5325

    To resolve the issue. Please perform below steps:

    1. Login to SCFM using partner email id.

    2. Go to System Management > Account Settings > Synchronize and click on Synchronize button to sync the partner data

    3. After account synchronization is complete, please check your devices will display in Device Discovery tab of SCFM or not?

    Ravi

Reply
  • Hi John,

    Thank you for providing the requested detail. I have checked the issue and found issue as bug.

    Reference id: NCCC-5325

    To resolve the issue. Please perform below steps:

    1. Login to SCFM using partner email id.

    2. Go to System Management > Account Settings > Synchronize and click on Synchronize button to sync the partner data

    3. After account synchronization is complete, please check your devices will display in Device Discovery tab of SCFM or not?

    Ravi

Children
  • I can now see devices and they now appear in Central Firewall Manager but I can not get them to Synchronize

    Under Status they are not connected and show as Incompatable

    Advise as to the next step to correct

    Thanks

  • Hi John,

    Have you allowed HTTPS access  for WAN in all 3 devices on Device Access page? If not then please allow it and check the status of the issue.

    I have checked and found CFM is not able to connect to all 3 appliances on 4444 port. It is getting connection time out error.

    If you do not wish to open HTTPS access for WAN in XG then you can create local acl rule on Device access page for CFM using below configuration.

    Steps to create local ACL rule for CFM:
    ·         Go to System > Administration > Device Access in XG.
    ·         Enter CFM Domain Rule Name.
    ·         Select IPv4 as IP Family, WAN as Source Zone.
    ·         Add the Network/Host created for the IP address “us-e1.cfm.sophos.com” i.e. 52.0.39.131
    ·         Select HTTPS as Services and Accept as Action.
    Click Save.

     

    Ravi

  • Ravi

    HTTPS access for WAN is allowed on all three devices on Device Access page.

    I will add the rule and test the access.

    Thanks

  • Hi John,

    I have checked the issue and found all 3 devices are showing sync in CFM. Please check the status of the issue.

    Ravi

  • Ravi

    All 3 devices are showing sync in CFM

    Thanks for your help on this issue.

    I consider this issue as closed.

    On another matter:

    I have another XG105 firewall that is showing as disconnected.

    The logs accessed from the gui show that nothing has been sent to CFM

    It is getting updates for antivirus according to the logs

    I do not have console access to this device as it is at a remote location.

    Thanks

  • Hi John,

    Thank you for update.

    CFM/SFM show device as disconnected when there is connectivity issue between XG and CFM. When XG device failed to send heatbeat packets to CFM/SFM then SFM/CFM declare device as disconnected.

    Please check XG device is sending Heart Beat packets to CFM or not in /log/garner.log from advance shell.

    Ravi

  • Ravi

    I cannot get to advanced shell I do not have access to the console as the xg device is at a remote site

    The xg system logs that i can see from the gui on the device show that no heartbeat is being sent from device to CFM

    John

  • Hi John,

    It seems like XG is not able to send heartbeat packets to CFM.

    Please check in XG device that you are able to resolve CFM domain name us-e1.cfm.sophos.com ?

    If you have configured secure syslog port to 6514 then please change to HTTPS and check heartbeat packets get send in GUI system logs of XG.

    Ravi

  • Ravi

    I am able to resolve CFM domain name us-e1.cfm.sophos.com to required IP

    I changed central management from syslog to HTTPS on port 443

    The xg is set synchronization mode for: Device will fetch configuration changes from Central Management

    I checked the logs of the xg and it still shows: 

    Failed to send heartbeat from device to sfm   Message id 17910

    and

    Failed to send information collection from device to sfm Message id

    John

  • Hi John,

    It looks like there is communication problem between CFM and XG device.

    PM device serial number which is disconnected. I will check the issue and get back to you.

    Ravi