This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG V18 MR3

Hello Sophos,
can we still expect the XG V18 MR 3 this week ?




[locked by: FloSupport at 4:35 PM (GMT -7) on 13 Oct 2020]
Parents Reply
  • I can only recommend you one thing ... Don't.  v18 is mostly about two things.  Decoupled NAT, and TLS/SSL Inspection rules.  The later does not work.  Source of continous problems and slowing down everything to a crawl.  You can live with coupled NAT. So. Wait at least another year.  Seriously.  Other wise you'll be part of Sophos Q&A team liking it or not.  And your customers will want to hang you.

    Paul Jr

Children
  • is right about the TLS/SSL Inspection Rules; it just doesn't work.  You will pull your hair out trying to troubleshoot why sites randomly either fail to load or load extremely slowly.  Loved getting the panic call from our HR people who couldn't process payroll because the site wouldn't load halfway through.  The answer you'll get from Sophos is "Make an exception" but when you observe that somewhere around 30% of sites have problems, that's not a practical or realistic or serious answer.  

    Part of the reason I've been so interested in MR3 is the hope that there are major improvements to the TLS/SSL engine, but I'm not holding my breath anymore.  

  • Make exception rules was what I was told too.  If you look at Sophos own built-in exception rules (for Microsoft updates for example), you'll notice that many of them disable ssl inspection very widely to a point it is not usefull anymore.

    Paul Jr