Hello Sophos,
can we still expect the XG V18 MR 3 this week ?
[locked by: FloSupport at 4:35 PM (GMT -7) on 13 Oct 2020]
Hello Sophos,
can we still expect the XG V18 MR 3 this week ?
Thanks Jonnie,
I think that gives me some good information. I think I'm going to disable 2FA for IPsec / SSL VPN as I can use certs and only enable it for the user portal. This stops people from downloading the config with a compromised account if it happens but keeps the user experience optimal. At least until it works better...
EDIT: Well damn I found that green thing you asked if it was a bad joke... I guess that makes sense, I was starting to find 4/ 8 hour connection issues. Mostly 4 hours as we moved many of the systems to IPsec because the SSL VPN clients weren't seemingly playing as nice as I'd like... or something. We just did for fun. Though I remember seeing 4 hours in some logs, the tickets lay out a 4-5 hour window and the one from last night was 8 hours exactly. It's very noticeable when they suddenly have to enter their 2FA code again so I'm disabling it on everything but the user portal for now. Jeesh. Thanks again for helping out that VPN tumor that has been growing :S
Glad to hear! =)
Beside from disabling the 2FA, you can easily set the Maximum Session Limit at the XG to 12 hours, if it reasonable for your network. We did this also for our ssl vpn clients and there are no further disconnects.
Yea. We also have most people using IPsec with the new connect thing haha. The hard coded timeout crap. Though with the new 2.0 client, I think we can get them back to SSL VPN as it seems to work nicely. I started the discussion internally so that's fun. Stupid rekey time thing with 2FA hah.
Hello Tom,
I am very much looking forward to their "high quality standards". I do not remember that in the last 2 to 3 years, any version of XG v18 MRx would be without errors and subsequent bug fixes in the next MR version.
I'm really looking forward to it!
But maybe they want to pleasantly surprise us all ....
Regards
alda
P.S. I think we could objectively expect high quality standards at Check Point, palo alto networks, ForcePoint and Cisco, but Sophos? That will be a really big surprise.
Hello Tom,
I am very much looking forward to their "high quality standards". I do not remember that in the last 2 to 3 years, any version of XG v18 MRx would be without errors and subsequent bug fixes in the next MR version.
I'm really looking forward to it!
But maybe they want to pleasantly surprise us all ....
Regards
alda
P.S. I think we could objectively expect high quality standards at Check Point, palo alto networks, ForcePoint and Cisco, but Sophos? That will be a really big surprise.