Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread)

Release Post:  Sophos Firewall v21 Early Access Announcement 

Whats New Link: https://assets.sophos.com/X24WTUEQ/at/7t8k46h9ttmxt6pn8g58k7wb/sophos-firewall-key-new-features-v21.pdf 

Please provide feedback using the option at the top of every screen in your Sophos Firewall as shown below or via the Community Forums.

NOTE: Sophos Firewall v21 does NOT include support for XG and SG Series appliances. XG Series EOL is March 31, 2025.
XG/SG Hardware will find them self until the EOL on the V20.0 Branche with MR2 + 
Sophos SFOS Home users are not affected, as SFOS Home is running the software version. 

For LE Related config issues, please review this post first:  Let´s Encrypt Deep Dive & Debugging in SFOSv21.0  



LE
[bearbeitet von: LuCar Toni um 8:59 AM (GMT -7) am 31 Aug 2024]
Parents
  • Just some thoughts from myself about the 3th Party Feed feature in SFOSv21.0

    SFOSv21 offers a option to import open or closed Thread feeds to the firewall and interact with it (primarily blocking or monitoring). 
    While this invites an admin to import all available lists in the internet, this should be done by caution. 
    There are some lists in the internet, which are not well curated - They are full with false positives and/or not including many real use cases. 
    One example is, some IP Lists simply listing parts of content deliver networks (CDN) IPs, which are used by millions of clients. 

    Depending on the quality of the lists, the experience can be different. 

    One important point: All Sophos SFOS Network protection customers (like Sophos Home) have access to the x-Ops Feeds: https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/ActiveThreatResponse/ActiveThreatResponseSophosXOpsThreatFeeds/index.html (Sophos X-Ops threat feeds was previously called Advanced threat protection (ATP).)
    This list is curated and managed by Sophos and a method used by Sophos for over 15 years. 

    I recommend to see this new feature as a addition to the X-Ops Feed and not adding every feed you can find out there to avoid false-positives in the first place. 

    __________________________________________________________________________________________________________________

Reply
  • Just some thoughts from myself about the 3th Party Feed feature in SFOSv21.0

    SFOSv21 offers a option to import open or closed Thread feeds to the firewall and interact with it (primarily blocking or monitoring). 
    While this invites an admin to import all available lists in the internet, this should be done by caution. 
    There are some lists in the internet, which are not well curated - They are full with false positives and/or not including many real use cases. 
    One example is, some IP Lists simply listing parts of content deliver networks (CDN) IPs, which are used by millions of clients. 

    Depending on the quality of the lists, the experience can be different. 

    One important point: All Sophos SFOS Network protection customers (like Sophos Home) have access to the x-Ops Feeds: https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/ActiveThreatResponse/ActiveThreatResponseSophosXOpsThreatFeeds/index.html (Sophos X-Ops threat feeds was previously called Advanced threat protection (ATP).)
    This list is curated and managed by Sophos and a method used by Sophos for over 15 years. 

    I recommend to see this new feature as a addition to the X-Ops Feed and not adding every feed you can find out there to avoid false-positives in the first place. 

    __________________________________________________________________________________________________________________

Children
No Data