This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Need Information: What is needed for Remote Access to a XG with factory default settings and no internet?

Hi,

Support want´s to have access in a remote session to a XG that has factory setttings and the internet connection is not configured?

How would the support team get access to this hardware from India?



This thread was automatically locked due to age.
  • yes, sophos can´t reproduce this behavior with a XG 230.

    I can´t restore this backup into a virtual SFOS (17.5.14). log says that a SG210 backup can´t be restore into SFOS ...

  • See https://support.sophos.com/support/s/article/KB-000036245?language=en_US for more information. 

    What happen, if you reimage your appliance with the current installation and restore the backup? This should actually resolve your problem. There is some old data in your config database, conflicting with the migration. 

  • The matrix seems to be incorect, as i can´t restore a SG210r1 Backup into a virtual SFOS.

    SG210r1 has 6 physical NIC´s without Flexi Port. And some VM´s i tried had 6 NIC. And i can´t create a Hyper-V with more than 8 v NIC s. I needed to ad Legacy NIC´s to the VM, but this give more problems. 

    I tried that more than once, most of the time the debug log in SFOS claims, that a SG210 can´t be restore ...

    What do you meen with reimage?

  • The Matrix shows "NO" for backup from 1U/2U Appliances to a virtual Appliance. 

    If you use a ISO stick and simply reinstall the XG firewall. This will reset the configuration database. Importing your Backup should resolve this issue going forward. 

    Another approach would be, to let Sophos Support edit the configuration database and start to investigate, why there are configuration settings in your database, which cannot be migrated. Seems to be a (very?) old setting, which is not be usable anymore. 

  • I read the matrix with the Flexi Port Option in a different way...

    without Flexi module option = there is no module installed!

    So if the "not installed module" means, that a SG/XG 210 can´t have 14 NIC´s i understand that it doesn´t work.

    But it was possible to me to restore into a virtual SFOS with 11 NIC´s (i will try again).

    Sophos has the ticket since 05.09 and they don´t talk about editin some database...

    So maybe if i just remove the MIME selection but keep File Protection enabled, the database might be good.
    I will see / test this in 75 Minutes ...

  • The matrix is showing the size of the appliance. Separated between 1U/2U Appliances and Desktop appliances. (One with flexiport the other without). 

    So Support cannot access your appliance? Because such changes are likely firstly to be investigated via Support channel before going into the config database. 

  • I will try to give them acces, but they had access for about a week, and i don´t know if they did this already.
    They only checked some things and told me to disable the MIME settings in the policy.

    I will try a forth time today and maybe we can get an remote access over a second WAN connection.

    Would a "Wipe Disk" with a USB Stick (Tool) of the appliance and a reinstall of 17.5.12 work?
    Reload the Backup and "ALL Settings" will be back?

  • Hi, good news.

    The new attempt faild the same way, but i connect to the factory default XG 17.5.14-1 an uploaded the MR14 backup.
    The one without the MIME white list Filters and SMTP Policy File Protection still enabled.

    After some endless minutes the XG 17.5.14-1 was back again and accepted the old MR14 backup file.

    If i check the MIME whitelist i see what sophos did.
    They changed the default MIME whitelist filters.

    I think all is fine now.

    Thanks for your Help LuCar Toni!