Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After Upgrade to v18.0 MR4 Auxillary Appliances boots in Failsafe Mode - Reason "Unable to apply NAT Rules"

Hi,

today i upgraded an Sophos XG Cluster from v18.0 MR 3 to v18.0 MR 4.

Everything looked fine, so i did an Failover check, Afterwards not all outgoing WAN Connection possible.

After some checks we recognized that the Appliance booted in the Failsafe mode.

After another Failover the Primary Appliances booted also in Failsafe Mode so the Problem was persistent.

So i decided to rebuild the HA Cluster, after i disabled it and rebooted the now Standalone Appliance, everything was working correctly.

After a Factory Reset for the Auxillary Device, i rebuild the Cluster.

Sadly the now Auxillary Appliance booted again into Failsafe Mode, the Reason is:

"Sophos Firmware Version SFOS 18.0.4 MR-4

failsafe> show failure-reason
Unable to apply NAT Rules"

Has anyone an Idea how i find out more details?

The Cluster has two WAN Interfaces

There are still several auto created and linked NAT Rules and SD-WAN Rules from the Migration from SFOS 17.5 to v18.0 MR3.

Sincerly

Gordon Leisering



This thread was automatically locked due to age.
Parents
  • We have exactly the same problem. 

    After the upgrade GUI Access worked fine and the HA status was okay.

    Next day customer reported, that outgoing traffic is not possible, although remote access to the box worked fine. 

    from the livelog i quickly noticed, that all traffic hits nat Rule "0" and not any of the MASQ Rules. 

    I had to create a now default MASQ to fix the issue.

    Futhermore a VPN Tunnel config was gone. 

    when SSH into the firewall, i noticed the device is in failsafe mode. 

Reply
  • We have exactly the same problem. 

    After the upgrade GUI Access worked fine and the HA status was okay.

    Next day customer reported, that outgoing traffic is not possible, although remote access to the box worked fine. 

    from the livelog i quickly noticed, that all traffic hits nat Rule "0" and not any of the MASQ Rules. 

    I had to create a now default MASQ to fix the issue.

    Futhermore a VPN Tunnel config was gone. 

    when SSH into the firewall, i noticed the device is in failsafe mode. 

Children
  • FormerMember
    0 FormerMember in reply to Samuel Heinrich

    Hi Samuel, We believe this needs further in-depth investigation from our support team to help you find the root cause and resolve the issue. I would recommend you open up a support case and you can share the access ID via a direct message so that we can keep a track of it.