DO NOT INSTALL 9.703-2!!!
My lab system was Up2Dated to 9.703-2 Thursday evening at 10PM CDT (UTC -0500) and all connection with the outside world immediately stopped. My local connection would work normally a few minutes at a time and then everything would lock up for a few minutes. I could not identify the problem with top, but did see a lot of zombie confd processes. I lost the entire day of Friday because my wife has a big project due next week and was working via Microsoft Teams all day with her colleagues.
I will suggest to Sophos that the file be removed from the ftp site. Grumble.
Cheers - Bob
Ugly. I was unprepared for disaster recovery with my wife working from home. I found out that my USB stick that hadn't been used in over a year was dead as was the monitor connected to the UTM that hadn't been turned on probably since I replaced the computer several years ago. Oh, and I was reminded that my client that borrowed my portable DVD burner had never returned it. Here's an extract from the case I have open with Sophos Support...
My initial attempt to fix this problem was to restore from a backup made automatically the morning before the 9.703 Up2Date was applied. That had no effect, so I rebooted the UTM (a UTM 320 running as a generic PC). Again, the problems continued.
Note: I don't remember if I changed /etc/asg five years ago after installing an ssi ISO or if I changed it before installing an asg ISO. That might be something to test: https://community.sophos.com/products/unified-threat-management/f/hardware-installation-up2date-licensing/10917/asg-425-display-with-homelicense/32959#32959
First, more description of the situation. Both Reporting and the logs showed that there was no more traffic on the External interface after the reboot following the application of the Up2Date at 22:00 local time on 09 April.
Something was causing things to lock up for several minutes and then work for several minutes. I decided that I would capture all of the logs from 2020 using WinSCP.
When the "lock" was on:
Strangely, top on the console continued running. I was surprised that there were so many confd zombies. Another big user of CPU was mdw - which made no sense to me as I was changing nothing. At one point, during a lock, I noticed httpproxy take 95% of one CPU, so I waited for WebAdmin to be responsive again and disabled Web Filtering and Snort. That made no difference and the lock-work cycle continued.
Finally, I was able to get all of the 2020 logs from /var/log, re-imaged with 9.702 (asg ISO) and restored from backup. All is now running normally as it was prior to installing 9.703.
Thanks for a thorough walthrough of your isses.
I installed 9.703 when it came out on 1 SG 210, and have not seen anything yet, regarding issues - no explosions.
I run it as ASG (Software) on the appliance to use the home / partner license :)
Looking forward to hear your feedback ;)
Happy easter ;)
Sophos XGA 2100 @ Home | Sophos v19 Architect
Just updated a UTM 220 with ASG (Software) 9.703 also, there is also no issues....
Hello, just to second Bob: I also had this problem. Although I cannot technically verify it as he was able to (due to my lack of knowledge), it felt exactly as Bob described, extreeemly sluggish and strange, and as I posted here:https://community.sophos.com/products/unified-threat-management/b/blog/posts/utm-up2date-9-703-released
The effects of the upgrade were for me the same as for Bob. Maybe as additional info: my hardware is a Fujitsu-PC with home edition. Intel i5-4590, 12GB RAM, 1x Intel NIC onboard, 2x Intel NIC I210-T1, 1x HDD.