Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG115W daily crashes after v18 MR5 upgrade Build 586

We updated XG115W from 17.5 MR15 to v18 MR5 on Sunday. Since that upgrade the firewall has crashed every evening. The entire system stops responding.

- VPN goes down
- WebAdmin page does not respond.
- Firewall logs stop logging any activity in any log
- All internet access is down

After a reboot, the system acts normally for a period of time.

Firewall has an SSL site to site VPN and a basic rule set to allow most traffic to the internet with ATP and IPS.

It is a fairly basic setup that was working fine before the v18 upgrade.

They are a public utility and daily outages are not really acceptable.

Anyone got any ideas?



This thread was automatically locked due to age.
Parents
  • Hello Brent,

    Thank you for contacting the Sophos Community, sorry to hear you are having issues with your device.

    If you have a case open with Support could you please share the Case ID with me, so I can follow up, if you haven't please open one and share the Case ID with me.

    Can you please submit the following files:

    csc.log, applog.log, syslog.log, msync.log and networkd.log

    Memory and CPU graph and all this detail with exact date and time when issue observed.

    If you have any log under /var/cores, please submit the output of the command.

    Also the output of this command:  grep 'NMI\|backtrace' /log/syslog.log

    Additionally please run the following command, to disable Firewall-Acceleration and monitor if the issue happens again.
    console> system firewall-acceleration disable
    To see if the Firewall Acceleration is enabled, please run
    console> system firewall-acceleration show

    Note: If disabling Firewall Acceleration, does temporarily resolve the problem, this still needs to be investigated. 

    I'd also suggest you set up a console connection to capture the next restart event if it ever happens. 

    Regards,

  • Support asked for a copy of cores.sslvpn from /var/cores but I am unable to transfer that file, I don't have permissions. Thoughts?

  • How big is this file? Copy it to /tmp/ and use (p)scp to copy it from there. 

  • I copied it to temp, but I had to CHMOD before I could download it... Thanks for the idea to make a copy!  :)

Reply Children
No Data