Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 18.5.2 - "Port" is now "system-reserved" in the interface name?

Test device: XGS 107

Firmware: SFOS 18.5.2 MR-2-Build380

On the latest firmware, when we try to change the interface name to our default naming scheme ("Port"/"VLAN" <Number> <Name>) (ex: "Port 2 Comcast WAN"), we get the following error:

"This is a system-reserved interface name. Specify a different name."

We can switch to using "Interface" instead of "Port", but this is still very troubling. We have a LOT of firewalls in the field with this naming scheme. What is going to happen when those get firmware upgrades? Is this just a bug? Should we skip upgrading, or do we need to manually change all of our interface names on our whole fleet of firewalls first?

For reference, this behavior did not happen on SFOS 18.5.1 or before.



This thread was automatically locked due to age.
  • Hi  Thank you for reaching Sophos community team. I would suggest to opening a support case to have further investigation OR if there is an existing support case you may share the ID with us - so we may review the case and do the needful to have the next progress.

  • Hello Joshua,

    Thank you for contacting the Sophos Community.

    We were able to replicate this, I will check internally if this was intended from this version or might be a coding error. 

    If you have already opened a Case as Vishal recommended, please share it with me

    Regards,

  • Hello Joshua,

    Just to let you know that is under DEV now, with ID issue NC-84555

    Regards,

  • Hi Joshua

    We use a similar naming scheme, with "port" in it, and noticed the same behavior with 18.5.2. we didnt had any trouble applying the firmware upgrade 18.5.2 with this naming scheme. Its just not possible to rename the interfaces according to the naming scheme, with the new firmware 18.5.2.

    I'm glad to see, this is under DEV already. Hope to see a fix soon.

    Regards

  • Hello Joshua,

    DEV has mentioned this is an intentional change taken during the implementation of NC-62120 (Related to issues with backups when the name of interfaces is changed), this also includes beside "port", "eth" or "ge". 

    This restriction was added for add/edit interface only.

    NC-84555 will be published as KIL, and the documentation will be updated accordingly. 

    Regards,

  • We hit this recently and after dealing with support were a bit disappointed to be advised this change is permanent and they are simply matching on the letters "ge" and not doing any kind of validation that it's the interface name ge0 or eth12 etc that they are looking for. So the word "General" gets flagged as an invalid port name. But yet add an extra letter to the start like "iGeneral" and it works fine.

    I've argued with support about this really should have been a basic regex match rather than just literally the first two characters so they have created this suggestion idea here.

    ideas.sophos.com/.../44962132-revision-for-nc-85343