I am trying to get HA up between two Sophos Firewall VM's. Both VMs are run using QEMU on the servers.
The first VM is running on a HP Proliant Gen8 with Unraid . (I have been running a Sophos Firewall on this machine for several years)
The second…
Hello, in the last weeks our XGS2100 Firewall cluster rebooted itself a few times - and there's no real pattern.
Without warning I receive this email:
Dear Administrator, You are receiving this auto-generated message from Sophos Notification System…
Hello,
I am looking to confirm if the below is feasible.
We have a HO and BO. The BO hosts a number of production servers and so there is an SD-WAN Connection Group that connects the two firewalls and allows certain services to certain VLAN networks…
Hi All,
We have 2 Sophos XG Firewalls setup in HA and using NTLM / Kerberos authentication.
We notice that in Active directory there is only one firewall computer account showing and was wondering if that is ok or if there should be 2 accounts …
Hi, I tried to access the auxiliary devices of several our customers via an ssh tunnel using "ssh -D 7777 admin@firewall.customer.xyz" and than using localhost:7777 as socks proxy in Firefox. There I use the peer administration IP on port 4444 to access…
I need to know which of these files ( ctsyncd.log, applog.log, msync.log ) or another log shows me the communication between Sophos A and Sophos B (Active and Passive Ha Mode) about changes from active to passive firewall. How do I identify this in the…
Hi there,
we are just implementing a management vlan in our network. Therefore I added the mgmt-vlan on one of our 2 main-connections to the coreswitch. Management of switches and servers is working properly.
Last step would be to manage our XGS active…
Hello everyone,
I need to upgrade the SSDs in a customer's HA cluster, and it is not clear to me how to proceed.
From the guide:
"High availability
In an HA cluster, you must upgrade the SSD firmware on each appliance individually as follows:…
I started the SSD firmware update KB-000045380 on XGS136 HA A/P Cluster.
First I applied the update to the AUX node 2. It was successful and the machine re-entered the cluster and A/P cluster was all green in the end.
I switched the PRI HA node from…
Hi,
I have a SFV4C6 (SFOS 19.5.3 MR-3-Build652) running standalone as a VM, and I need to HA pair it.
I am unable to find an SFV4C6 image to use, does this mean I am unable to HA this existing appliance?
We have XGS4500 active-passive cluster and i stubled across a pretty annoying issue.
In the past (with XG450 and others) we always set the peer administration address to something that allowed us no monitor the auxilary device via our monitoring solution…
Mostly the title, but I have Sophos XG 136’s in HA mode. Have a backup internet line, on port 3 (main WAN is port 2). The status red/green icon shows red. But if I go into diagnostics, I can ping out on port 3. I can also confirm from outside of the network…
Hi all, my setup at home is the following.
I have a proxmox host on which I have created an active/passive HA installation of SFOS v20. HA is connected and all green. When I try to register this installation to Sophos central, only the active peer is…
Hello,
Two XGS3300 in an working Active/Passive Cluster, not working after the update to 20.0.
I deleted the Cluster and tried to re-establish it but it fails all the time.
I tried several times with Quick HA or Interactive Mode.
Tried with VLAN…
Hello,
I just got a quick question about the replication behavior of HA mode. We just turned off the SIP ALG module on the active XGS FW. So now I wonder if the same module is turned off on the passive XGS? Side question can I connect with ssh to the…
Just wondering, I have an 19.5.3 HA cluster
Node 1 shows 5 computers with missing heartbeat. 2 are over 100 days old.
Now after switching HA nodes manually (Node 2 manually rebooted first) Node 2 shows only 3 computers, all are older than 100…
Hi everyone,
Currently we have Sophos xg 230 in our network and it is HA. Our Primary fw is (Active) and Secondary is Auxillary (passive).
So I want to update firmware of Sophos XG 230 which is already in HA mode, So what should I do or what will…
Figured as since I cannot find anyone else experiencing this issue, wanted to highlight this here if it helps someone else or if Sophos want to investigate themselves. FW type, config and version in subject. TLDR: Disable HA if you experience issues with…
Just to confirm
HA requirements - Sophos Firewall
DHCP and PPPoE: When the interfaces are dynamically configured using DHCP or PPPoE, the following applies:
Active-active mode: Not supported.
Active-passive mode: Supported, but session failover…
Boa tarde / Good afternoon
Preciso de uma maneira de cancelar a aplicação de uma nova licença/subscrição no firewall Sophos XG em HA, pois devido a manutenção dos servidores de licenciamento meu firewall não mantém acesso via GUI e CLI.
I need a…
I'm trying to lab out a Sophos XG HA under a three server VMware cluster. DRS and HA are disabled on the VMWare cluster.
XG Firewall A is on VMware Server 1
XG Firewall B is on VMware Server 3
VMWare server 2 is not relevant to this issue.
Both…
Hello,
Yesterday we have upgraded a Sophos XGs cluster to firmware 19.5.3 MR3-build652 and we noticed that one of the 2 nodes was greylisting e-mails coming from addresses that have e-mailed this organization in the past. Once we failed the nodes over…
Hi, I have to change the HA link port for a customer. The reason is that it is to be upgraded to fibre I have no physical access to the HA cluster! Is there a good way to do this, or is it (as I fear) necessary to dissolve the HA cluster and create a…