Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread)

Release Post:  Sophos Firewall v21 Early Access Announcement 

Whats New Link: https://assets.sophos.com/X24WTUEQ/at/7t8k46h9ttmxt6pn8g58k7wb/sophos-firewall-key-new-features-v21.pdf 

Please provide feedback using the option at the top of every screen in your Sophos Firewall as shown below or via the Community Forums.

NOTE: Sophos Firewall v21 does NOT include support for XG and SG Series appliances. XG Series EOL is March 31, 2025.
XG/SG Hardware will find them self until the EOL on the V20.0 Branche with MR2 + 
Sophos SFOS Home users are not affected, as SFOS Home is running the software version. 

For LE Related config issues, please review this post first:  Let´s Encrypt Deep Dive & Debugging in SFOSv21.0  



LE
[bearbeitet von: LuCar Toni um 8:59 AM (GMT -7) am 31 Aug 2024]
Parents
  • Thank you for finally listening to the users and implementing LE support. I will say that you guys have left out some of the CA's though. You have the ISRG X1, and X2 root certs, along with the R3 Intermediate. However, you did not add the E5, and E6 X2 signed, and cross-signed X1 CA's to the trusted list. This is needed for any connection that is performing a more in-depth inspection of the traffic. Notably how I found this was with my Bitwarden android app's connection to my ValutWarden self-hosted instance. Once I added this to the trusted store, the connection started to work as expected. Please fix this in the next EAP, or before the GA is released. It may be advantagious to add R10 and R11 Intermediate certs as well. 

  • "finally listening to the users" um, I doubt it's been a case that they've been ignoring users and finally decided to throw an intern at it last week or something. There are multiple steps behind the scenes -- including allowing the WAF subsystem participate in the process whether you have a WAF license or not, etc. And I'd imagine anything they did that automatically adds and deletes rules needs to be very thoroughly handled, not to mention adding regularly-scheduled events to renew, etc.

    So, yeah, it's finally been released, but it's not like they weren't listening.

Reply
  • "finally listening to the users" um, I doubt it's been a case that they've been ignoring users and finally decided to throw an intern at it last week or something. There are multiple steps behind the scenes -- including allowing the WAF subsystem participate in the process whether you have a WAF license or not, etc. And I'd imagine anything they did that automatically adds and deletes rules needs to be very thoroughly handled, not to mention adding regularly-scheduled events to renew, etc.

    So, yeah, it's finally been released, but it's not like they weren't listening.

Children
No Data