DO NOT INSTALL 9.703-2!!!
My lab system was Up2Dated to 9.703-2 Thursday evening at 10PM CDT (UTC -0500) and all connection with the outside world immediately stopped. My local connection would work normally a few minutes at a time and then everything would lock up for a few minutes. I could not identify the problem with top, but did see a lot of zombie confd processes. I lost the entire day of Friday because my wife has a big project due next week and was working via Microsoft Teams all day with her colleagues.
I will suggest to Sophos that the file be removed from the ftp site. Grumble.
Cheers - Bob
Ugly. I was unprepared for disaster recovery with my wife working from home. I found out that my USB stick that hadn't been used in over a year was dead as was the monitor connected to the UTM that hadn't been turned on probably since I replaced the computer several years ago. Oh, and I was reminded that my client that borrowed my portable DVD burner had never returned it. Here's an extract from the case I have open with Sophos Support...
My initial attempt to fix this problem was to restore from a backup made automatically the morning before the 9.703 Up2Date was applied. That had no effect, so I rebooted the UTM (a UTM 320 running as a generic PC). Again, the problems continued.
Note: I don't remember if I changed /etc/asg five years ago after installing an ssi ISO or if I changed it before installing an asg ISO. That might be something to test: https://community.sophos.com/products/unified-threat-management/f/hardware-installation-up2date-licensing/10917/asg-425-display-with-homelicense/32959#32959
First, more description of the situation. Both Reporting and the logs showed that there was no more traffic on the External interface after the reboot following the application of the Up2Date at 22:00 local time on 09 April.
Something was causing things to lock up for several minutes and then work for several minutes. I decided that I would capture all of the logs from 2020 using WinSCP.
When the "lock" was on:
Strangely, top on the console continued running. I was surprised that there were so many confd zombies. Another big user of CPU was mdw - which made no sense to me as I was changing nothing. At one point, during a lock, I noticed httpproxy take 95% of one CPU, so I waited for WebAdmin to be responsive again and disabled Web Filtering and Snort. That made no difference and the lock-work cycle continued.
Finally, I was able to get all of the 2020 logs from /var/log, re-imaged with 9.702 (asg ISO) and restored from backup. All is now running normally as it was prior to installing 9.703.
I have also just tried an upgrade and the exact same thing happened.
although 2 hours after it performed the upgrade it sent out a backup file.
I have had no connection to the outside world or any of the VLANs internally.
I also noticed that the interfaces would all shutdown (no lights) and then start back up again after a few minutes.
I am now having to re-image the entire SG310.
I am realising that trusting Sophos to do their job, is not working out well (what with the RED issue).
it is a great product, but they keep on screwing up.
XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!