Restricted Advance Shell - examples of challenges

Hi Community contributors,

Starting Sophos Firewall v19, with the addition of many comprehensive logging enhancements in the GUI, and in-line with industry best-practices, access to the Advance Shell is restricted to licensed commercial versions of the product.

Partners and certified architect engineers have an option with Not-for-Resale license to set up labs or customer PoC with unrestricted advanced shell. Also, Sophos Support is able access the Advanced Shell via support access channel. Hence, in case of critical issues, support can still can access it.

Sophos Firewall has been incrementally improved since v18 with comprehensive logging enhancements in the GUI (Better search, filtering, configurations, SD-WAN logs, VPN logs, gateway logs etc). However, we acknowledge that Advance Shell restriction might have created challenges in certain database related configurations, especially for home users.

Please help us understand the specific examples of challenges you face due to this restriction - configurations where GUI and console tools are reaching the limits. We will suggest the possible workaround for the specific scenario. We will also plan and gradually improve the product for those scenario.

Sincerely,

Sophos Firewall Product Team

Parents Reply Children
  • No. Business XG's are also affected. You are aware that business XGs do also run on evals before subscriptions are being activated? E.g. when doing fresh install or first setup? For registration and licensing, webadmin access is necessary. So if I deployed a XG before any subscriptions are active, I will also not be able to access the Advanced Shell e.g. to change interface configuration in order to access WebAdmin in Cloud Deployments. Without Advanced Shell, there is no way around this "core issue". Tell me, how would you set up a v19 cloud XG in e.g. IONOS Cloud? Do you tell your partners and customers, they have to install a windows vm to access the XG webadmin locally from inside the datacentre? They will ditch the product right away.

  • That is correct. There is currently no workaround in case you cannot register the appliance in the first place. That is the reason, we are asking for such feedback, so Sophos can pick up those requirements. 

    About the installation process. Does IONOS support templates? Because "officially supported public cloud vendors" like AWS, Azure have templates of SFOS pre installed in there marketplace. 

    __________________________________________________________________________________________________________________

  • It's useless to argue any further. Let Sophos taste their own medicine. No advanced customers anymore with V19.

    They clearly showed, how they care about us and the answer is, not a single second. The "what are the challenges" only appeared, after the community called out the removal of the advanced shell multiple times. They could've just started this exact thread like a year ago and presented us a V19 EAP with a sufficient CLI, so that there is no need for a shell, but they did not. Tells me, they don't care about their customers in any way.

    Nothing against LuCar Toni. He is just here to help, but honestly the ship has already sailed.

  • Throwing something out like that and just wait if an outcry from your customers/partners happens is plain cheeky and as you said: if it would've mattered to improve the product, there would've been much better ways, but this wasn't their intention. Just after they realized that they messed up, they came around with this thread. On the other hand, this is the exact bad behaviour I would've expected from Sophos.

  • Thanks for your Feedback. 

    __________________________________________________________________________________________________________________

  • Come on LuCar, we all know that Sophos doesn't care about feedback at all.