This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG210 - Upgrade from 17.5.12 MR-12 to 18.0.1 MR-1-Build396 - major problems

Hi,

Attempted an upgrade as per subject for a client.

We experience the following issues:

1. Random issues with traffic flow. Some servers could ping across the router to the internet randomly.

-- This turned out to be fixed by disabling hardware acceleration.

 

2. IPSEC Site-to-site VPN with policy routing (to AWS)

-- No traffic would flow across the IPSEC link until i enabled NAT. Using conntrack to identify the sessions - it looked correct and matched. Firewall policy test evaluated as expected. I tested with ping from the firewall, and that got through to the remote network ok.

 

3. Remote users connecting in with L2TP VPN

-- On V17, this was rock solid. On V18 the VPNs were randomly dropping. There were LCP errors in the log as well.

 

4. Voice quality - Phones connect (routed) across the Sophos between two local LAN segments.

-- On V17, this was fine. On V18, it sounded like there was constant very low packetloss, or perhaps the occasional packet experiencing jitter. It sounded like there were weird compression artifacts or something.

 

We've given upSophos engineer rolled back to V17 and all these problems seemed to go away.

 

Googling around shows we're not the only ones experiencing these weird problems.

 

 

Is this typical for the 'upgrade pain' to V18?

Is V18 ready for production use?



This thread was automatically locked due to age.
Parents
  • IPsec Tunnel to AWS: Nevertheless what you did in the past, would recommend to move to VTI (route based) in V18 to connect aws/azure. This should be better in any case. 

     

    Did you disable the DPI Engine? Did this solve anything? 

     

  • Seems to still be a bug. Tried upgrading 17.5.14 to 18 MR3. starting getting constant hauser can't login alerts. tried rebooting, but its not coming back online now.

  • Is'nt it unbelievable that Sophos still has a broken upgrade path in their major product line? They know, that v17 and v18 have incompatible HA communication and this is not fixable? Even worse, they actively block the old HA partner because they don't speak the same language. I wonder how many hours in crashed HA environments have been exhausted.

    You will have to do a manual upgrade of the v17 node and then do your best to get them together into HA. If you call support, you will have this situation for some days.

Reply
  • Is'nt it unbelievable that Sophos still has a broken upgrade path in their major product line? They know, that v17 and v18 have incompatible HA communication and this is not fixable? Even worse, they actively block the old HA partner because they don't speak the same language. I wonder how many hours in crashed HA environments have been exhausted.

    You will have to do a manual upgrade of the v17 node and then do your best to get them together into HA. If you call support, you will have this situation for some days.

Children