This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM v.9.005015 Soft-Release

We just uploaded the UTM 9.005 Up2Date package to our FTP servers as  soft-release.  Please kick the tires and give it a try.

Angelo incoming:
9.005 contains a ton of compatibility improvements and stability enhancements for your Sophos UTM 9 release. In addition to adding official support for our new RED50 appliance, we have worked very hard to polish up the Web Filter and Wireless Protection areas of UTM 9, optimizing memory usage/consumption while plugging a few pesky memory leaks! The WAF has been improved with several bug fixes, and some reporting issues were also addressed. Internally, we have almost 100 issues that were addressed across many areas. For the best UTM 9 experience, you can install this soft-release now, or wait for the official GA in a weeks time (targeted estimate). Note that with the new incremental update system in UTM 9, if we do make changes to the GA from the soft-release issue, your installation will Up2date at that time without the need to roll back or perform command line trickery like editing the version number.
Enjoy! Let us know what you think, the dev's, myself, and other staff will monitor this thread until the GA Release.
/Angelo



Sophos UTM v.9.005015 Soft-Release

News

  • Support for RED50 appliances
  • Stability fixes for Web Filter
  • Stability fixes for Wireless APs
  • Bug fixes for Application Control
  • Updated timezone definitions


Remarks

  • System will be rebooted
  • Configuration will be upgraded
  • Connected Wifi APs will perform firmware upgrade
  • Connected RED devices will perform firmware upgrade


Bugfixes

  • 21785 Transparent Authentication does not work for IPv6 when SSL scanning is active
  • [V9] Form Hardening blocks request due to missing token, although URL Hardening Exception should allow access
  • 22456 Empty graphs in Hardware and Network Usage
  • 23179 Form Hardening doesn't support image type input form buttons


Download:
Up2Date Link: http://ftp.astaro.com/UTM/v9/up2date/u2d-sys-9.005015.tgz.gpg
Up2Date MD5Sum Link: http://ftp.astaro.com/UTM/v9/up2date/u2d-sys-9.005015.tgz.gpg.md5
Size: ~107 MB
MD5Sum: 0856b37fdf8060b8fac1710d7e0036f1


This thread was automatically locked due to age.
  • Noticed this after the 9.005 up2date (may have been there before) in the Application Control Log:

    2013:02:13-00:20:52  afcd[5408]: [in_private.c]:91: conn=0x0000470D src=[.14]:8751 dst=[]:3101 (TCP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-00:59:39  afcd[5408]: [in_private.c]:91: conn=0x00003E03 src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-02:41:48  afcd[5408]: [in_private.c]:91: conn=0x0000541D src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-04:24:49  afcd[5408]: [in_private.c]:91: conn=0x000062DD src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-05:15:18  afcd[5408]: [in_private.c]:91: conn=0x000079E2 src=[]:64181 dst=[]:80 (TCP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-06:07:49  afcd[5408]: [in_private.c]:91: conn=0x00007317 src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-07:50:24  afcd[5408]: [in_private.c]:91: conn=0x000081A9 src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-09:32:59  afcd[5408]: [in_private.c]:91: conn=0x00009031 src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-10:40:13  afcd[5408]: [in_private.c]:91: conn=0x0000B204 src=[]:50797 dst=[]:80 (TCP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-11:15:08  afcd[5408]: [in_private.c]:91: conn=0x0000A504 src=[.90]:55246 dst=[.255]:3052 (UDP) flags=CLASSIFIED afcd.conf classification limits are exhausted
    2013:02:13-12:11:59  afcd[5408]: [in_private.c]:91: conn=0x0000C154 src=[00.1]:47060 dst=[00.10]:80 (TCP) flags=CLASSIFIED afcd.conf classification limits are exhausted

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • THanks, didn't see that thread in the beta.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • dies this mean application control in 9.005 doesn't work?

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I installed 9.005-15 on a productive Astaro, system still filling the swap up and up, but till now no connection failures or slow website replies.

    more or less still existing problems
    Any questions or support response (also via PM) would be great!

    ---

  • how much ram is in the box..which features are on and how many users?

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Here everything is ok ...
    10 UTM 220, 8 ASG 120 and 5 virtual appliances.

    Nice Job! [:D]
  • UTM 220 9.005-15 w/ 50 users without any servers (web, email, voip, etc)...CPU is at >90%… still observing behavior of the device...i think it was really under size...
  • how much ram is in the box..which features are on and how many users?


    Hardware Appliance ASG220 rev 5 (white), 2GB(?) RAM, Full Guard with ~35 Users

    ---

  • dies this mean application control in 9.005 doesn't work?

    it works. the log message isn't very harmfull. It just means, that there has been a flow which couldn't be classified fast enough.
    This noisyness will be removed in upcoming releases.