This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG V18 MR3

Hello Sophos,
can we still expect the XG V18 MR 3 this week ?




[locked by: FloSupport at 4:35 PM (GMT -7) on 13 Oct 2020]

Top Replies

  • Update: SFOS v18 MR3 has been released
    Please see - https://community.sophos.com/xg-firewall/b/blog/posts/xg-firewall-v18-mr3 

    Hi All,

    Here's the latest update:

    As with any release for XG Firewall, ensuring high quality and a great customer experience is our top priority with MR3.  For this reason, we generally do not make timing commitments for Maintenance Releases and only publish them once they meet our high quality standards. MR3 is a substantial release, integrating a number of security and performance enhancements as well as a significant number of fixes. We know there is high anticipation amongst partners and customers for many of these enhancements and are working as fast as possible to get it into their hands. We expect to release it next week but as mentioned, quality is our top priority and that will determine the release timing.

    Jump to answer
Parents Reply
  • I can only recommend you one thing ... Don't.  v18 is mostly about two things.  Decoupled NAT, and TLS/SSL Inspection rules.  The later does not work.  Source of continous problems and slowing down everything to a crawl.  You can live with coupled NAT. So. Wait at least another year.  Seriously.  Other wise you'll be part of Sophos Q&A team liking it or not.  And your customers will want to hang you.

    Paul Jr

Children
  • is right about the TLS/SSL Inspection Rules; it just doesn't work.  You will pull your hair out trying to troubleshoot why sites randomly either fail to load or load extremely slowly.  Loved getting the panic call from our HR people who couldn't process payroll because the site wouldn't load halfway through.  The answer you'll get from Sophos is "Make an exception" but when you observe that somewhere around 30% of sites have problems, that's not a practical or realistic or serious answer.  

    Part of the reason I've been so interested in MR3 is the hope that there are major improvements to the TLS/SSL engine, but I'm not holding my breath anymore.  

  • Make exception rules was what I was told too.  If you look at Sophos own built-in exception rules (for Microsoft updates for example), you'll notice that many of them disable ssl inspection very widely to a point it is not usefull anymore.

    Paul Jr