This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPv6 in broken state

IPv6 has been unuseable latetly. Its not just about the unsupported PD-IA over PPPoE which has not been fixed since i reported it 1 1/2 years ago (several times and in beta), but with the last few updates IPv6 seems to only work in midnight during full moon if you spell the right chants. Sometimes it works, sometimes i need to restart the UTM a few times turn off/on IPv6.

Is anyone else having these problems?

If Sophos is reading this: when are you going to fix remaining buggy implementation?



This thread was automatically locked due to age.
Parents
  • opened a Ticket through our Partner on Jan 5th 2017 (#6865033) - no reaction so far. Also bought another Sophos UTM that will serve IPv6 Endpoints eventually. Will see how it works out.

    ---

    Sophos UTM 9.3 Certified Engineer

Reply
  • opened a Ticket through our Partner on Jan 5th 2017 (#6865033) - no reaction so far. Also bought another Sophos UTM that will serve IPv6 Endpoints eventually. Will see how it works out.

    ---

    Sophos UTM 9.3 Certified Engineer

Children
  • Ticket through our Partner got closed by Sophos due to not having gold status or better.

    I opened up a new ticket on a licenced SG230 that ia also opened for support, ticket ID #7001011 and communicated this.

    let's see where this leads and if we can get a fix after over 2 years.

    ---

    Sophos UTM 9.3 Certified Engineer

  • our own (new) ticket also got closed due to the need of having a partner with gold/platinum status

     

    tldr: no gold/platinum partner, no support from sophos!

    ---

    Sophos UTM 9.3 Certified Engineer

  • Ben said:

    our own (new) ticket also got closed due to the need of having a partner with gold/platinum status

     

    tldr: no gold/platinum partner, no support from sophos!

     

    ah that's interesting...and would explain why Sophos routinely ignores my tickets and requests for service and why i am ignored by my sophos reps except for buying things.  I always thought Sophos didn't give two craps about silver partners..this is confirmation.  

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • UPDATE: Sophos created a private patch for our UTM that fixes/enabled ipv6 prefix delegation over pppoe! I am testing this patch right now and i suspect (but can't say for sure) that they will include it in one of their next patches (at least that would make sense, sophos has not said that they will do that, so its me speculating that they will)

    i will post the BUG ID here so that anyone affected by this bug can ask their sophos partner to request this bugfix and have it installed (IF thats how "it" works)

    Edit/Update: The fix works and the BUG ID is "NUTM-7187"

    Edit2: Hold your breath, delegated ipv6 prefix doesn't work after 24-48 hours, i will try to file a new bug report tomorrow. It seems the utm doesn't renew the prefix after the lease time runs out. Probably a slight oversight...

    ---

    Sophos UTM 9.3 Certified Engineer

  • this does not help Ethernet connections though.  Sophos is constantly having to disable things that work everywhere else due to their poor code quality standards.  Also consider that most new features in terms of integration within their stack no goto XG.  SG is simply a cash cow they can milk until XGT is where they want it...SG(Astaro) days are numbered.  That in conjunction with their abuse of silver partners has led me to begin moving my clients to another platform.  It's too bad Astaro has gone down the crapper like it has..i used to be one of it's bigger advocates.....

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • So I did bail on Sophos but I haven't forgotten those still suffering. I came across a bug in the Router Advertisement daemon on another router; it wouldn't start if more than two IPv6 DNS servers were specified. I'm sure I had at least 4 configured on my UTM. Anyway, try removing all IPv6 (or all but two) DNS servers from your UTM configuration (maybe reboot or turn off and on the IPv6 functionality to ensure the services are [re]started).

    BTW My APs for salered 50