This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG V18 MR3

Hello Sophos,
can we still expect the XG V18 MR 3 this week ?




[locked by: FloSupport at 4:35 PM (GMT -7) on 13 Oct 2020]
Parents Reply Children
  • Thanks Jonnie,

    I think that gives me some good information. I think I'm going to disable 2FA for IPsec / SSL VPN as I can use certs and only enable it for the user portal. This stops people from downloading the config with a compromised account if it happens but keeps the user experience optimal. At least until it works better...

    EDIT: Well damn I found that green thing you asked if it was a bad joke... I guess that makes sense, I was starting to find 4/ 8 hour connection issues. Mostly 4 hours as we moved many of the systems to IPsec because the SSL VPN clients weren't seemingly playing as nice as I'd like... or something. We just did for fun. Though I remember seeing 4 hours in some logs, the tickets lay out a 4-5 hour window and the one from last night was 8 hours exactly. It's very noticeable when they suddenly have to enter their 2FA code again so I'm disabling it on everything but the user portal for now. Jeesh. Thanks again for helping out that VPN tumor that has been growing :S

  • Glad to hear! =) 

    Beside from disabling the 2FA, you can easily set the Maximum Session Limit at the XG to 12 hours, if it reasonable for your network. We did this also for our ssl vpn clients and there are no further disconnects. 

  • Yea. We also have most people using IPsec with the new connect thing haha. The hard coded timeout crap. Though with the new 2.0 client, I think we can get them back to SSL VPN as it seems to work nicely. I started the discussion internally so that's fun. Stupid rekey time thing with 2FA hah.