This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9.601 - RED issues!

Since upgrading all our customers to 9.601, a bigger part of them are complaining about RED's re/disconnection in a no-pattern way.

It started for all of them just the night we upgraded to 9.601, and they all are on different ISP's and located different places around the country.

Been with Sophos support for 2 hours today, and now they escalated it to higher grounds.

Will return with an update....

Suspicious entries in the log - but all connected REDs do this before connection:

2019:03:06-15:15:38 fw01-2 red_server[17509]: SELF: Cannot do SSL handshake on socket accept from 'xxx.xxx.xxx.xxx': SSL connect accept failed because of handshake problems

2019:03:06-15:15:46 fw01-2 red2ctl[12420]: Missing keepalive from reds3:0, disabling peer xxx.xxx.xxx.xxx

I know the last line is written before the tunnel disconnects, because there was no "PING/PONG" answer...

One customer has 2 x RD 50, one 1 100% stable and the other fluctuates in random intervals - we replaced this with a new RED 50, but the same thing occurs.



This thread was automatically locked due to age.
  • regarding 9.7   

     

    https://community.sophos.com/kb/en-us/134717

     

     

    Sophos is investigating reports from some customers experiencing RED site-to-site tunnel issues after upgrading from v9.605 to v9.7.

  • neildonaldson said:

    regarding 9.7   

     

    https://community.sophos.com/kb/en-us/134717

     

     

    Sophos is investigating reports from some customers experiencing RED site-to-site tunnel issues after upgrading from v9.605 to v9.7.

     

     

    yes that was with 9.700-4, it's fixed in 9.700-5 :-)

     

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Technician

  • When did 9.7 come out?? The UTM I'm looking at right now still says 

    Firmware version:   9.605-1

    and no updates are available. To add insult to injury - one of the Red 15wi tunnels to a site office has just gone down again (despite the disabling of the Unified Firmware). Seems to only be good for a max of two weeks and I have to send a tech back out ... kinda glad I don't have 50 (or more) of these like other blokes. Starting to re-think the entire network infrastructure at this point. Having this drag on for months is ridiculous.

  • Dread said:

    When did 9.7 come out?? The UTM I'm looking at right now still says 

    Firmware version:   9.605-1

    and no updates are available. ...

     

     

    The release will be rolled out in phases.

    • In phase 1 you can download the update package from the download area.
    • In phase 2 we will make it available via our Up2Date servers in several stages.
    • In phase 3 we will make it available via our Up2Date servers to all remaining installations.

    So, I think Sophos is still in phase 1. See https://community.sophos.com/products/unified-threat-management/b/blog/posts/utm-up2date-9-700-released for the download links.

    Best regards

    Alex

    -

  • I am glad this forum is here!

    As I have an open ticket with support and have done since the original advisory came out, I would have expected Sophos to tell me about the updates (both of them)!

    I have now replied to the emails asking for more information.

    XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)
    Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!

  • So I had previously switched to the non Unified Firmware for my RED 15s (all my REDs are RED 15s) which helped noticeably but we were still experiencing random dropouts of random REDs.  As of now I have upgraded manually to 9.700-5.  My question is do I need to re-enable/switch back to Unified Firmware or not?

     

    Thanks,

    Tracy 

  • Check the status by going to the command line and issue command "cc get red use_unified_firmware"

    If it returns a 1 then your upgrade has automatically turned the Unified firmware back on. In previous upgrades this was the default behavior. See previous posts in this thread about the best way to perform an upgrade and still retain the old RED firmware on the devices.

     

    Whether or not you "need" to be on the Unified firmware is a matter of choice. I am still seeing people here reporting big problems with the Unified firmware (note Twisters many issues). I am not using the Unified firmware until I am convinced the issues have been completely fixed.

  • I checked after the upgrade and can confirm that it *DID NOT* switch back to unified firmware.  The cc get red use_unified_firmware returned a 0 on both my UTMs after the upgrade.

     

    I am going to monitor the logs closely for the next little while an see what if anything happens.

     

    Tracy

  • Tracy Carlton said:

    I checked after the upgrade and can confirm that it *DID NOT* switch back to unified firmware.  The cc get red use_unified_firmware returned a 0 on both my UTMs after the upgrade.

     ...

    These are very good news for anybody struggling with the update to 9.7. Thank you for sharing that. It seems Sophos has learned a little bit from the updates since 9.601.

    Best regard

    Alex

    -

  • It started for all of  xenderthem just th omegle e night we upgraded to 9.601, and they all are on discord  different ISP's and located different places around the country.