This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[CRIT-026] License usage: EXCEEDING 110% OF USER COUNT on Sophos UTM (naughty router doing proxy-arp, and nmap, sigh) - will it 'come good' ?

Hi Folks,

I've been using UTM 9 in a VM (actually a pair of them for master/slave HA) on home license for a while now, loving the UTM after getting to know its' quirks and bugs and working around them (really wish they'd make IPv6 work properly..  Not installing a default route is really annoying..).

I 'lost' a device in the DC (one of two VLAN's serviced directly on the UTM - everything else is routed via the UTM) a couple of days ago, so did a ping scan with nmap, to try and find it's IP.   Which was when I discovered one of my Mikrotik routers was doing proxy-arp on the DMZ vlan, even though it doesn't have an IP there, and since then I've been getting an email every 12 hours from the UTM :\

I've found many posts on here about resetting the license counts, which cleans up the issue - for 12 hours!  Can I just keep running the two commands to do the licensing count reset every 12 hours, and after a set amount of time the UTM will stop thinking it has 255 devices? Or am I going to have to format and reinstall the two UTM VM's and restore from backups?

This seems like yet another huge bug in the UTM?  If they're going to take an arp response as evidence of a 'user', there should be a simple way of forcing a recount?  I only have one LAN segment which is directly handled by the UTM (the others are all routed via OSPF and arrive via ADSL/NBN/MWB connections from home, our parents, our 3G devices, etc), and it's making me think I should take that VLAN away from the UTM and route it behind a Mikrotik to the UTM as well.. :\

Thanks for your help :)



This thread was automatically locked due to age.
  • The licence count will either reset in 7 days or 48 hours, can't remember what the current setup is.

    If you only have one network why do you need a router, wouldn't a managed switch do? The UTM can do your routing.

    If you set the router up correctly and have it be the gateway then the UTM will not see all the addresses only those that talk to the UTM.

    Set the router up as your DHCP server.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks mate, I'll just keep resetting the count until it hits the 7 days (as it's now at 4 days, so past the 48 hours), and see how it goes :)

    I have more than one network - just only two are handled by the UTM directly (The DMZ - a public /28, and the DC LAN - a /24 of private space with ~20 VM's and DRAC/iLO devices on it) - everything else is routed via OSPF on the mikrotik's

    I moved the DC LAN to the UTM early on when I was having issues with doing VRF's with VRRP on the mikrotiks, though I mostly have those sorted now, so could move the DC LAN vlan back to the 'tiks.  

    Thanks,

    Damien