Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread)

Release Post:  Sophos Firewall v21 Early Access Announcement 

Whats New Link: https://assets.sophos.com/X24WTUEQ/at/7t8k46h9ttmxt6pn8g58k7wb/sophos-firewall-key-new-features-v21.pdf 

Please provide feedback using the option at the top of every screen in your Sophos Firewall as shown below or via the Community Forums.

NOTE: Sophos Firewall v21 does NOT include support for XG and SG Series appliances. XG Series EOL is March 31, 2025.
XG/SG Hardware will find them self until the EOL on the V20.0 Branche with MR2 + 
Sophos SFOS Home users are not affected, as SFOS Home is running the software version. 

For LE Related config issues, please review this post first:  Let´s Encrypt Deep Dive & Debugging in SFOSv21.0  



LE
[bearbeitet von: LuCar Toni um 8:59 AM (GMT -7) am 31 Aug 2024]
Parents
  • Will there be a software image for XGS Hardware? To be able to use a home license on XGS hardware? I bought 2 XGS and can't use it.

  • Hi,

    i tried the other way (Editing the BIOS from EFI shell), but had no luck.

    I have an old XG115w and changed the Product, Version and Serial inside the BIOS/DMI Settings into an XGS87, XGS107 or XGS116w.

    This is the boot screen of a XG115w Stuck out tongue winking eye

    Version 2.18.1263. Copyright (C) 2018 American Megatrends, Inc.
    BIOS Date: 02/08/2018 18:18:39 Ver: 5.0.1.2
    BIOS Build Info: Rev Z131-015 (02082018)
    Sophos XGS 107_SN01
    CPU: Intel(R) Atom(TM) Processor E3940 @ 1.60GHz Speed:1600MHz
    Mem: 4096MB (DDR3 1600) (A-DATA)

    But the HW-21.0.0_EAP1-152 installer only says ...

    Appliance not detected
    GPIO number is reserved
    press y to reboot

    So, maybe you could change the Product, Version and Serial from your XGS Models to another Product or Vendor.
    May the SW-21.0.0_EAP1-152 installer would work on a edited XGS Hardware?

  • I know, but what *if" the Software installer doesn´t detect any XGS Hardware?

    in a few weeks I'll have 2 old XGS2100 systems, so I'll give that a try.

  •  Could you briefly explain how you did this with the bios? I have a bios programmer.

    Gruß

    Andreas

  • The information is all at your own risk. (No BIOS programmer was necessary).

    The following steps were necessary to adjust the settings on the XG115w.

    First, create a USB stick with FAT32 and set up an EFI shell (info on this can be found at Thomas Krenn).
    Copy the AMIDMI tools to the stick (they are freely available on the net, just search for “DMI Edit via Windows or EFI for AMI BIOS”). maybe the version plays a role.

    Now start the hardware, change the boot order in the BIOS and switch from Legacy to UEFI. Now you only have to boot from the USB stick, the EFI shell boots automatically and the DMI variables can be read out and changed with the AMIDMI tools.

    Finally, switch back from EFI to Legacy BIOS.

    Good luck!

    I tried the HW Image and the SW Image on Virtual Box emulated XGS.

    The HW image reads some some information from DMI Vars during installation and fails.
    The SW image reads the variables DmiBoardProduct/DmiSystemProduct as XGS and refuses to install.

    After changing these DMI Vars in the Virtual Box XGS, the SW Installer started installation and finished.

    Therefore, for XGS hardware, I would set the variables DmiBoardProduct/DmiSystemProduct to XG or any other value.

    Give this a try at your XGS Hardware

  • So I was actually able to install it. But no network drivers are loaded now. The drivers are present in the HW image, but they are missing in the SW image.

  • Hi,
    I have got the same issue with SFOS 20.0.0 and 20.0.2
    Interfaces on a Intel hardware (not Sophos!) don´t show up.

    When you go to bootloader / troubleshooting the interfaces show up, but not in Sophos Firewall.

    As we use more or less simular hardware for more then 4 Years with a couple of hundred Devices this is strange.

    But as it not relevant for this discussion (21.0 EAP) I´ll open tickets, as Central also refuses to push templates.

Reply
  • Hi,
    I have got the same issue with SFOS 20.0.0 and 20.0.2
    Interfaces on a Intel hardware (not Sophos!) don´t show up.

    When you go to bootloader / troubleshooting the interfaces show up, but not in Sophos Firewall.

    As we use more or less simular hardware for more then 4 Years with a couple of hundred Devices this is strange.

    But as it not relevant for this discussion (21.0 EAP) I´ll open tickets, as Central also refuses to push templates.

Children
No Data