Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread)

Release Post:  Sophos Firewall v21 Early Access Announcement 

Whats New Link: https://assets.sophos.com/X24WTUEQ/at/7t8k46h9ttmxt6pn8g58k7wb/sophos-firewall-key-new-features-v21.pdf 

Please provide feedback using the option at the top of every screen in your Sophos Firewall as shown below or via the Community Forums.

NOTE: Sophos Firewall v21 does NOT include support for XG and SG Series appliances. XG Series EOL is March 31, 2025.
XG/SG Hardware will find them self until the EOL on the V20.0 Branche with MR2 + 
Sophos SFOS Home users are not affected, as SFOS Home is running the software version. 

For LE Related config issues, please review this post first:  Let´s Encrypt Deep Dive & Debugging in SFOSv21.0  



LE
[bearbeitet von: LuCar Toni um 8:59 AM (GMT -7) am 31 Aug 2024]
Parents
  • (English version below)

    Hallo zusammen,

    ich habe die EAP Version 21 gestern auf meiner privaten Firewall zu Hause installiert. Es handelt sich hierbei nicht um Sophos Hardware. Die guten Punkte vor weg, das Upgrade verlief Problemlos und die GUI ist nun deutlich schneller als es zuvor der Fall war.

    Mit zwei Punkten habe ich allerdings noch so meine Probleme.

    - Lets Encrypt
    Ich habe auf der Firewall die entsprechende Lets Encrypt Registrierung vorgenommen und versucht für zwei Domains, welche auf die WAN Seite der Sophos zeigen versucht ein Zertifikat auszustellen. Leider war das für beide Domains nicht erfolgreich. Die Zertifikate stehen zwischenzeitlich beide im Fehlerstatus.

    "type":"urn:ietf:params:acme:error:connection"
    "detail":"87.XXX.XXX.222: Fetching home.my.domain/.../kivhVYa8PXXXXXXXXXXXXXXXPIvCHWkT5iAFa1L0e7Q: Error getting validation data"
    "status":400

    das andere Zertifikat steht ebenfalls im Fehlerstatus, allerdings nur mit dem Fehler "http request error".

    - Third-party threat feeds
    Ich habe mehrere Feeds auf der Firewall eingetragen. Allerdings bleibt die Anzahl der Indicators immer bei 0 stehen. Beispiel feed: raw.githubusercontent.com/.../diamondfox_panels.txt

    Ich habe heute noch ein paar feeds hinzugefügt und erhalte nun im feed Status die Meldung "Storage full". Wenn ich mir die Speicherauslastung der Sophos ansehe, ist allerdings noch ein guter Teil des Storages frei.

    SFVH_SO01_SFOS 21.0.0 EAP1-Build152# df -h
    Filesystem Size Used Available Use% Mounted on
    none 1.5G 1.2M 1.4G 0% /
    none 2.9G 424.0K 2.9G 0% /dev
    none 2.9G 44.0M 2.9G 1% /tmp
    none 2.9G 53.6M 2.9G 2% /dev/shm
    tmpfs 2.9G 0 2.9G 0% /sys/fs/cgroup
    /dev/boot 126.2M 34.7M 88.8M 28% /boot
    /dev/mapper/mountconf
    950.7M 87.8M 846.9M 9% /conf
    /dev/content 11.2G 543.3M 10.6G 5% /content
    /dev/var 87.1G 22.7G 64.4G 26% /var

    Wir bekomme ich die beiden Probleme am besten bereinigt?

    Grüße aus Deutschland!

    Hello everyone,

    Yesterday, I installed the EAP Version 21 on my home firewall, which is not Sophos hardware. On the positive side, the upgrade went smoothly, and the GUI is now significantly faster than before.

    However, I am facing two issues:

    - Let’s Encrypt:
    I registered Let’s Encrypt on the firewall and attempted to issue certificates for two domains that point to the WAN side of the Sophos. Unfortunately, the issuance was unsuccessful for both domains, and the certificates are now showing an error status.

    "type":"urn:ietf:params:acme:error:connection"
    "detail":"87.XXX.XXX.222: Fetching home.my.domain/.../kivhVYa8PXXXXXXXXXXXXXXXPIvCHWkT5iAFa1L0e7Q: Error getting validation data"
    "status":400

    The other certificate also shows an error status, but with a simpler "http request error."

    - Third-Party Threat Feeds:
    I have added several feeds to the firewall, but the number of indicators remains at zero. For example, the following feed: raw.githubusercontent.com/.../diamondfox_panels.txt.

    I added a few more feeds today, and now the feed status shows "Storage full." However, when I check the storage usage on the Sophos, a significant portion of storage is still available.

    SFVH_SO01_SFOS 21.0.0 EAP1-Build152# df -h
    Filesystem Size Used Available Use% Mounted on
    none 1.5G 1.2M 1.4G 0% /
    none 2.9G 424.0K 2.9G 0% /dev
    none 2.9G 44.0M 2.9G 1% /tmp
    none 2.9G 53.6M 2.9G 2% /dev/shm
    tmpfs 2.9G 0 2.9G 0% /sys/fs/cgroup
    /dev/boot 126.2M 34.7M 88.8M 28% /boot
    /dev/mapper/mountconf
    950.7M 87.8M 846.9M 9% /conf
    /dev/content 11.2G 543.3M 10.6G 5% /content
    /dev/var 87.1G 22.7G 64.4G 26% /var

    What would be the best way to resolve these two issues?

    Greetings from Germany!

  • For the thread feeds, share your insights here:  Sophos Firewall: v21.0 EAP1: Third Party Threat Feeds Discussions 

    For the LE Component: Could you share the support access ID with me?  

    __________________________________________________________________________________________________________________

  • Could you delete the German Post and we work on the english post? 

    __________________________________________________________________________________________________________________

  • It looks like your firewall is not getting the Port80 Packets. Is the forwarding of the NAT really working? 

    __________________________________________________________________________________________________________________

  • Think I could figure it out, where the Port 80 NAT Rule has issues. How can i trigger the LE verification?

  • Hi  ,

    SFOS clears the error states of the failed LE certificate requests overnight, and retries them.

    That means, when you have fixed the NAT rule, the LE certificate should be obtained in the next 24 hours the latest.

    You can send me an support access ID in a PM when ready, we can trigger the retry from the CLI too.

    Regards,

    Janos

  • Hi,

    I´ve added two LE certificates. On is issued the other remain at error state. I also set up the EA version on our datacenter firewall (no upstream NAT). There we have requested 3 LE certificates. One is issued, the other two also in error state. If I look at the reverse proxy log, I can even see the LE requests, bis they got http code 403.

  • Hi  ,

    can you please send (PM) me a support access ID for your system so that we can take a look?

    Thank you,

    Janos 

Reply Children