This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Forum for HA and Autoscaling UTM deployments @ AWS?

I feel like it would be beneficial to have a separate sub-forum specifically for discussing UTM deployments in the AWS environment.  Particularly for those of us working on getting the HA and/or Autoscaling implementations to work properly.  While the webpage here: www.sophos.com/aws seems to suggest that AWS integration is a widely used and perfectly tuned feature of the UTM, those of us who have been tinkering around with it know that Sophos still has a ways to go in ramping up their own internal expertise and supporting documentation for this use-case.    All the more reason for easy channels for collaboration among the community.

At the very least, I'd love to hear from anyone else out there who's currently working with the HA implementation.  I'm alternately impressed and frustrated with it thus far :)  but I think it could be a truly amazing product with a bit more fine tuning-- and I think strong community involvement is going to be the driving force to make that happen.  



This thread was automatically locked due to age.
  • Thank you for the update I went ahead and upgraded the existing firewall, to version  9409 as you can see in my screen shot below but I was unable to complete the HA setup still. Is there a reson why I cant deploy HA after the upgrade? Do i really need to launch a brand new instance from AWS market place first? If so which instance do I need Launch.

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • Thanks Vitale,

    There are two ways customers can update Sophos UTM on AWS. One way is via up2date, which I believe is the method you used. This update path is only available for our Stand Alone (Single AMI) release and uses the normal update process for all UTMs.

    Because our Auto Scaling and HA releases uses multiple AMIs, these releases don't update via up2date. Instead we've built a process called Cloud Update which uses CloudFormation stack updates to update the different AMIs. The conversion utility also uses CloudFormation stack updates as the process converts a Single AMI to multiple AMIs (depending on the option you choose). This means that the conversion utility won't work until (1) AWS publishes the latest AMI in the AWS Marketplace, and (2) we've updated our CloudFormation templates with the new AMI IDs (which AWS gives us).

    docs.aws.amazon.com/.../using-cfn-updating-stacks.html

    Again, we just pushed 9.409 to the AWS Marketplace yesterday. It usually takes AWS a couple of days to scan and publish them, with the holidays it may take a bit more. As soon as AWS comes back with the new AMI IDs, we'll update our templates and then the conversion utility should work. We'll let you know when we hear back from AWS.

    Hope that makes sense. If not, ping us via aws.maketplace@sophos.com and we can arrange a call.

    Thanks.

  • Hi.  I have been waiting for these AMIs to publish but it seems like it is taking longer than expected.   Do you have any kind of update on when they will be available?  I'm waiting to deploy a new single instance of 9.409 using HVM so that I can prepay for a reserved instance.

     

    Thanks!

     

    Tim

  • Hi Tim/Vitale,

     

    Apologies for the delay. The AMIs are now available. Let us know what you think. Thanks.

     

    community.sophos.com/.../sophos-utm-9-409-on-aws-release-notes

  • RichVorwaller

     

    I just tried HA (warm) standby I get the following precheck error.

     

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • Huston I think we have lift off after retring and waiting 5 min recreating IAM roles I think we have a conversion.

     

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • No the conversion failed and is rolling back who can call me 718-790-1150 and help me with this.

     

     

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • AWS stack error

     

    Events
    2017-01-07 Status Type Logical ID Status reason
      00:11:32 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::RouteTable RouteTable  
      00:11:30 UTC-0500 DELETE_COMPLETE AWS::EC2::Subnet Subnet2  
      00:11:29 UTC-0500 DELETE_COMPLETE AWS::EC2::Subnet Subnet1  
      00:11:29 UTC-0500 DELETE_COMPLETE AWS::EC2::Route Route  
      00:11:17 UTC-0500 DELETE_COMPLETE AWS::IAM::Role UTMRole  
      00:11:16 UTC-0500 DELETE_IN_PROGRESS AWS::IAM::Role UTMRole  
      00:11:15 UTC-0500 DELETE_COMPLETE AWS::EC2::SecurityGroup UntrustedGroup  
      00:11:15 UTC-0500 DELETE_COMPLETE AWS::EC2::SecurityGroup UTMSecurityGroup  
      00:11:15 UTC-0500 DELETE_COMPLETE AWS::EC2::SecurityGroup TrustedNetworkGroup  
      00:11:14 UTC-0500 DELETE_COMPLETE AWS::IAM::InstanceProfile UTMInstanceProfile  
      00:11:14 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::Subnet Subnet1  
      00:11:13 UTC-0500 DELETE_FAILED AWS::SNS::Topic UnhealthyTopic User: arn:aws:iam::525021013121:user/Sophos is not authorized to perform: SNS:DeleteTopic on resource: arn:aws:sns:us-east-1:525021013121:sophosHaWarm-UnhealthyTopic-QPUZOQHRU0JT
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::Route Route  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::SecurityGroup UTMSecurityGroup  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::Subnet Subnet2  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::IAM::InstanceProfile UTMInstanceProfile  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::SecurityGroup TrustedNetworkGroup  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::SNS::Topic UnhealthyTopic  
      00:11:13 UTC-0500 DELETE_IN_PROGRESS AWS::EC2::SecurityGroup UntrustedGroup  
      00:10:52 UTC-0500 ROLLBACK_IN_PROGRESS AWS::CloudFormation::Stack sophosHaWarm The following resource(s) failed to create: [Subnet1, UnhealthyTopic, UTMSecurityGroup, UntrustedGroup, Route, UTMInstanceProfile, TrustedNetworkGroup, Subnet2]. . Rollback requested by user.
      00:10:50 UTC-0500 CREATE_FAILED AWS::EC2::SecurityGroup UntrustedGroup Resource creation cancelled
      00:10:49 UTC-0500 CREATE_FAILED AWS::EC2::SecurityGroup TrustedNetworkGroup Resource creation cancelled
      00:10:49 UTC-0500 CREATE_FAILED AWS::EC2::SecurityGroup UTMSecurityGroup Resource creation cancelled
      00:10:47 UTC-0500 CREATE_FAILED AWS::EC2::Subnet Subnet2 Resource creation cancelled
      00:10:47 UTC-0500 CREATE_FAILED AWS::IAM::InstanceProfile UTMInstanceProfile Resource creation cancelled
      00:10:47 UTC-0500 CREATE_FAILED AWS::EC2::Subnet Subnet1 Resource creation cancelled
      00:10:47 UTC-0500 CREATE_FAILED AWS::EC2::Route Route Resource creation cancelled
      00:10:46 UTC-0500 CREATE_IN_PROGRESS AWS::IAM::InstanceProfile UTMInstanceProfile Resource creation Initiated
      00:10:46 UTC-0500 CREATE_FAILED AWS::SNS::Topic UnhealthyTopic User: arn:aws:iam::525021013121:user/Sophos is not authorized to perform: SNS:GetTopicAttributes on resource: arn:aws:sns:us-east-1:525021013121:sophosHaWarm-UnhealthyTopic-QPUZOQHRU0JT
      00:10:46 UTC-0500 CREATE_IN_PROGRESS AWS::IAM::InstanceProfile UTMInstanceProfile  
      00:10:41 UTC-0500 CREATE_COMPLETE AWS::IAM::Role UTMRole  
      00:10:40 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Route Route Resource creation Initiated
      00:10:39 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Route Route  
      00:10:35 UTC-0500 CREATE_COMPLETE AWS::EC2::RouteTable RouteTable  
      00:10:35 UTC-0500 CREATE_IN_PROGRESS AWS::SNS::Topic UnhealthyTopic Resource creation Initiated
      00:10:35 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Subnet Subnet2 Resource creation Initiated
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Subnet Subnet1 Resource creation Initiated
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::RouteTable RouteTable Resource creation Initiated
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::SNS::Topic UnhealthyTopic  
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Subnet Subnet2  
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::SecurityGroup UntrustedGroup  
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::RouteTable RouteTable  
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::Subnet Subnet1  
      00:10:34 UTC-0500 CREATE_IN_PROGRESS AWS::IAM::Role UTMRole Resource creation Initiated
      00:10:33 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::SecurityGroup TrustedNetworkGroup  
      00:10:33 UTC-0500 CREATE_IN_PROGRESS AWS::EC2::SecurityGroup UTMSecurityGroup  
      00:10:33 UTC-0500 CREATE_IN_PROGRESS AWS::IAM::Role UTMRole  
      00:10:28 UTC-0500 CREATE_IN_PROGRESS AWS::CloudFormation::Stack sophosHaWarm User Initiated

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • My username and access key policy for AWS sophos is below it has SNS in it why is it failing

     

     

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "cloudformation:CreateStack"
                ],
                "Resource": "*",
                "Condition": {
                    "ForAllValues:StringLike": {
                        "cloudformation:TemplateUrl": [
                            "https://s3.amazonaws.com/sophos-nsg-cf/*"
                        ]
                    }
                }
            },
            {
                "Effect": "Allow",
                "Action": [
                    "ec2:Create*",
                    "ec2:Describe*",
                    "ec2:AuthorizeSecurityGroup*",
                    "ec2:AllocateAddress",
                    "ec2:AssociateRouteTable",
                    "ec2:ReplaceNetworkAclAssociation",
                    "ec2:RevokeSecurityGroupEgress",
                    "ec2:TerminateInstances",
                    "cloudformation:Describe*",
                    "cloudwatch:PutMetricAlarm",
                    "autoscaling:Create*",
                    "autoscaling:Describe*",
                    "autoscaling:PutScalingPolicy",
                    "autoscaling:PutNotificationConfiguration",
                    "autoscaling:UpdateAutoScalingGroup",
                    "elasticloadbalancing:CreateLoadBalancer",
                    "elasticloadbalancing:ModifyLoadBalancerAttributes",
                    "elasticloadbalancing:SetLoadBalancerPoliciesOfListener",
                    "elasticloadbalancing:ConfigureHealthCheck",
                    "iam:CreateRole",
                    "iam:PutRolePolicy",
                    "iam:CreateInstanceProfile",
                    "iam:AddRoleToInstanceProfile",
                    "iam:PassRole",
                    "sns:CreateTopic",
                    "sns:ListTopics",
                    "sns:Subscribe",
                    "s3:CreateBucket",
                    "s3:Get*",
                    "s3:Delete*",
                    "s3:List*",
                    "s3:PutObject"
                ],
                "Resource": "*"
            },
            {
                "Effect": "Allow",
                "Action": [
                    "ec2:Delete*",
                    "ec2:DisassociateRouteTable",
                    "ec2:releaseAddress",
                    "autoscaling:Delete*",
                    "elasticloadbalancing:DeleteLoadBalancer",
                    "iam:RemoveRoleFromInstanceProfile",
                    "iam:Delete*"
                ],
                "Resource": "*"
            }
        ]
    }

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com

  • I added some more SNS actions.

     

                    "sns:CreateTopic",
                    "sns:Publish",
                    "sns:ListTopics",
                    "sns:Subscribe",
                    "sns:CreateTopic",
                    "sns:GetTopicAttributes",
                    "sns:ListSubscriptionsByTopic",

     

     

     

     

     

    Thank You

     

    Vitale Mazo

     

     

    Vitale Mazo | Senior Systems Engineer
    Novus Partners Inc | 200 Park Avenue, 27th Floor  | New York, NY 10166
    212.586.3030 Ext. 1093 | Cell: 718-790-1150 | Vmazo@novus.com