Next EAP release date?

Any word on when a EAP 2 refresh 1 or EAP 3 will be out?

This random reboot and loss of connection is killing me .

Parents Reply Children
  • Gentlemens, there is potential in DPI. Remember that this is an early access phase. Not everything goes well, some pages are not decrypted, but the mechanism itself seems to be OK. Let's give the Sophos a chance to prove themselves.

    The idea is innovative, but it needs to be refined. That is why we are a community to help in this. Instead of complaining, let's report bugs - thanks to this next releases will be much better.

  • , in my case DPI is introducing more issues than proxy. I am using SSL decrypt and scan since v16 and not big problem.

    , "the idea is not innovative". Other brands are using DPI since several years and I can remember the frustration at the beginning with another vendor when the customer moved from UTM 8 to the new brand. SSL/TLS was painful. Many websites stopped working.

    Using DPi is the way to go for a NGFW instead of UTM as the same packet is analysed once (or very few times) compared to UTM where the same packet is open/closed and analysed by many different engines.

    I fully understand how difficult is to integrate everything with snort engine but for the moment, a part my issue and some others, they did a great job with DPI. From v18 GA, DPI can only improve.

    XG suffers other big problems at the moment and I hope they listen and they stop to close features that are not yet completed, as they do not.

    Regards

  • You mean, that works very well with devices that you CAN install a CA?

    It won't work well on IoT because you CAN NOT install a CA.

     

    I just want to undestand you statment correctly.

  • Hi,

    you read my post correctly. I am using DPI on my IoT devices and they connect other internet where as the same devices with the web proxy and https inspection fail.

    I suspect the reason they connect is they are using the do not decrypt part of the web rule.

    I do find it a ;little sctrange in that I did create a ssl/tls specifically for my IoT devices that did not pass traffic even after I disabled the default rules.

    So a little unclear as to what is happening.

    Ian

     

    Update: - I looked the logviewer after 24hrs and found that two of IoT devices without CAs are passing the decrypt function in my TLS/ssl rule.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.