Sophos XG 17 RC1 - Can't login as Admin or User

Hey guys,


since beta 2 I have a sporadic problem with the authentication. After 2 days at the latest I can't log in to the admin interface, user portal or web authentication. The firewall practically freezes.
At the admin interface I get an error message that the login process failed. With incorrect credentials I get the same message.

When logging in to the User Portal or web-authentication I get no error message, only the loading graphic rotates with no result.
Logging on to the console is possible, but I cannot select an entry (1-7). The only fix is to reset the firewall.
I can't find any events in the syslog.

The XG firewall runs on an ESXi with 5GB Ram. In addition, a RED has been created and the user authentication runs via a domain controller.

While searching in the forum I came across older topics, but without a solution. Does anyone know the problem?

Regards

Parents
  • Mario, are you joking? Have you read the 2 pages of discussion?

    Here the problem in not login, but that the firewall became unaccessible and stops the dhcp server after a while, without any aparent reason! before it works fiine! I saw another error in web page . The Ram occupation is extremely different from the wab page to the advance shell

  • Don't know if the development team found the cause yet. I guess it is related to Advanced Thread Protection.

     

    It happened daily on my firewall. The worst case was 3 times a day. 

     

    I disabled the Advanced Thread Protection last week. The issue has not happened yet after 5 days running. 

     

    BTW, I also disabled HTTP scan for the primary firewall rule. However I have another zone and some other firewall rules, and they still have HTTP scan enabled. So that I believe it is the Advanced Thread Protection.

     

  • Hey guys,

    The Sophos team seems to have found the problem - probably this is caused by a system daemon. They have patched my firewall and since then it works without any problems.
    The fix is not public yet but i'm sure they release it in the next few days after additional monitoring.

    I don't want to anticipate too much, everything else will be published by Sophos / Deepti.

    Regards

  • I really hope they release the fix patch beacuse this problem is unbearable.

     
  • Hi,

    Thank you all for your feedback and extended support.

    We have already identified below issues whose end user symptoms are same but the issues are technically different.

    The patch is available and  will be also fixed in SFOSv17 MR1 release which will be soon. I am already in touch with the reported one users in PM for the feedback.

     

    The same issues are with the below thread as well.

    https://community.sophos.com/products/xg-firewall/sophos-xg-beta-programs/sfos-v170-beta/f/sfos-v170-beta-issues-bugs/97482/xg17-ga-bug

    The issue has been identified in race conditions and listed as below.

    NC-22472 - init/system process gets killed

    NC-23608 - Kernel crash issue during IPS signature upgrade

    NC-22950 - IPSec vpn up-down events causing system to be stuck

    Regards,

    Deepti

     

     

     

  • How can we get this patch? Ran into this problem this morning on a brand new install that's been running fine for about 4 days. Contacted support and they told me to reboot it (which was difficult because it's in a co-lo in another state, so had to wait about an hour with our whole company being offline until a contractor could get out there to power cycle it). The reboot did resolve it, but I'm assuming it is going to happen again in a few days. I pointed the support tech to this article, but he wasn't able to provide a patch. He said to just wait four more days to see if it happens again and then he would escalate it... Is there anything to check on the system to verify that this is the source of the problem? Would really like to not have our whole company spontaneously drop offline again.

Reply
  • How can we get this patch? Ran into this problem this morning on a brand new install that's been running fine for about 4 days. Contacted support and they told me to reboot it (which was difficult because it's in a co-lo in another state, so had to wait about an hour with our whole company being offline until a contractor could get out there to power cycle it). The reboot did resolve it, but I'm assuming it is going to happen again in a few days. I pointed the support tech to this article, but he wasn't able to provide a patch. He said to just wait four more days to see if it happens again and then he would escalate it... Is there anything to check on the system to verify that this is the source of the problem? Would really like to not have our whole company spontaneously drop offline again.

Children