This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 17.1.2 MR-2 . Really?

ALL,

 

i have upgraded the firmware from SFOS 17.0.8 MR-8 to SFOS 17.1.2 MR-2

 

i'm noticing alot of dropped packets that did not occur in the previous release. I'm probably going to roll back my upgrade.

 

Has something changed in the way the firewall is processing packets and/or rules?

 

I haven't changed anything other than upgrading as recommended.

 

The packets being dropped are occurring on allowed rules.



This thread was automatically locked due to age.
Parents
  • Hi,

    there is something wrong with your configuration, maybe? Why are the packets being dropped? Are any applications failing to connect or keep connected?

     

    please post a screenshot of your rule that https enabled?

    Ian

  • Do we talk about the invalid packet drops? Those are harmless.

    community.sophos.com/.../131754

  • sorry folks.

    Let me clearly explain. 

    I have not made any modifications to my policy after the upgrade. Everything theoretically should work as it was working in the previous release. 

    What I am experiencing now almost all the time on either large downloads, streams, etc. I'm seeing alot of RST packets and the connection either times out or the streams (youtube) disconnects and has to reconnect.

    This experience was not happening in the previous release. so to check my sanity I rolled back the upgrade and magically the connection was stable.

    Keep in mind this only occurs with either large downloads and/or when streaming. 

    So this isn't a deal breaker except for last night when I was watching a conference and the connection kept timing out.

    CPU is under 4%. 

    Memory is at 18-20% give or take.

    So I do not think this is a hardware issue as rolling back immediately fixed the problem.

    If someone has a link that shows all the changes in the new release that would be very helpful. Im guessing something has changed in how the firewall is now processing packets and/or handling large request. I sure hope Sophos has not implemented a technology like SecureXL which CheckPoint uses. 

    Thanks for all responses.

Reply
  • sorry folks.

    Let me clearly explain. 

    I have not made any modifications to my policy after the upgrade. Everything theoretically should work as it was working in the previous release. 

    What I am experiencing now almost all the time on either large downloads, streams, etc. I'm seeing alot of RST packets and the connection either times out or the streams (youtube) disconnects and has to reconnect.

    This experience was not happening in the previous release. so to check my sanity I rolled back the upgrade and magically the connection was stable.

    Keep in mind this only occurs with either large downloads and/or when streaming. 

    So this isn't a deal breaker except for last night when I was watching a conference and the connection kept timing out.

    CPU is under 4%. 

    Memory is at 18-20% give or take.

    So I do not think this is a hardware issue as rolling back immediately fixed the problem.

    If someone has a link that shows all the changes in the new release that would be very helpful. Im guessing something has changed in how the firewall is now processing packets and/or handling large request. I sure hope Sophos has not implemented a technology like SecureXL which CheckPoint uses. 

    Thanks for all responses.

Children