For those that upgraded, any risks of functionality breaking?
One concern I have is whether VPN users certificates will change and need re-enrollment?
This thread was automatically locked due to age.
For those that upgraded, any risks of functionality breaking?
One concern I have is whether VPN users certificates will change and need re-enrollment?
If you're upgrading from 18.5.2 MR2 and performing antispam filtering be aware that the antispam engine has been upgraded to SASI and the detection rates are truly abysmal. Wait for 19.0.1 MR1 and hope Sophos have fixed the detection rates. (NC-90702) is supposedly the fix for this.
The Links are online.
I have change the LAG at the Firewall from Auto-Negotiation to 10000 Full duplex -- > The LACP link come up.

After then I change back the LAG interface to Auto-Negotiation. It works..
Then I restart the Firewall and no LACP Link come up.
After reboot the interface get the right speed but the LAG become no speed information.

Any idea?
Yes. Configure a fixed speed. There is no disadvantage doing that.
Network devices behave sometimes different after updates etc. Probably some timing issue.
(I once had a similar issue when updating VMWare from 6.7 to 7.0. Took them more than a half year to fix this - never tested this though because we changed the way how the server was conneced from a (distributed) trunk to two single lines.)
Thank you for your support.
My system is now working very well.
Hello Pedro,
maybe you are affected by this one: https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/132121/ssl-vpn-ipv4-lease-range-changes-in-sfos-v19
Mit freundlichem Gruß, best regards from Germany,
Philipp Rusch
New Vision GmbH, Germany
Sophos Silver-Partner
If a post solves your question please use the 'Verify Answer' button.
A patch can be requested for v18.5 MR3 and v19 systems prior to the next releases by opening a Support Case.