Guest User!

You are not Sophos Staff.

  • I have executed  echo 30000 > /sys/class/net/wlnet/bridge/ageing_time 30000 on my system but issue is that guest network in separate zone does not came up. Again i have to delete the guest network and add back . I want know is the setting ageing time will restart persistent?

  • Interfaces are numbered i.e. wlnet1, wlnet2. Please check your config for proper interface name.

  • Yes Sir Checked they are wlnet wlnet1 wlnet3   and I have issue only on wlnet which is in separate zone.

  • I had a massive drop in memory usage (51% now) which appears to have occurred on 2 Aug at 15:37. The only pattern update around that time was the IPS and Application signatures at 15:30:20, Aug 02 2022. 

  • Thank you very much for flagging this shred. 

    We have identified an issue with ATP data update in MR1. The issue causes more memory to be consumed by IPS after the update, and the memory is not freed until an IPS sig update subsequently occurs. Last ATP data update was Monday Aug 1, which is when you saw the spike in memory. An IPS update was then done on Aug 2, which is why you saw memory usage drop back down. 

    We are now tracking this as a bug, and we're looking to release a new MR1 build with this fixed.  

  • Hi,

    Sorry for there delay in responding, I did not see your request until this morning. Do you still require access?

    The memory usage has dropped to 73% which is about normal for the XG115W.

    Ian

  • Yesterday we update XGS136 HA cluster from version SFOS 19.0.0 GA-Build317 to SFOS 19.0.1 MR-1-Build350 and all our WEB Servers(WAF Protection) stop working.

    Same thing happen when we update from SFOS 18.5 MR3 to 19 GA. Because I didn't have time to investigate problem in logs Im revert firmware back to 19GA and it still didn't work. Later Im upgrade back to 19 MR1 and investigate logs and see that is problem with WAF configuration file with "Cokie signing" function. We need disable that function on all WEB servers that service start working and then reenable it. 

    Im report this issue and open case 05574326.

    Before update all servers work normaly so is strange thing that revert back to previous image in GUI didn't wake up firewalls in working state as before upgrade!!!

    reverseproxy.log errors:

    AH00112: Warning: DocumentRoot [/sdisk/waffiles/e94c27e14abd78b16a3b25facdc5a436] does not exist
    AH00526: Syntax error on line 92 of /cfs/waf/reverseproxy.conf: Invalid encrypted key
    AH00112: Warning: DocumentRoot [/sdisk/waffiles/e94c27e14abd78b16a3b25facdc5a436] does not exist
    AH00526: Syntax error on line 92 of /cfs/waf/reverseproxy.conf: Invalid encrypted key
    AH00112: Warning: DocumentRoot [/sdisk/waffiles/e94c27e14abd78b16a3b25facdc5a436] does not exist
    AH00526: Syntax error on line 92 of /cfs/waf/reverseproxy.conf: Invalid encrypted key

    About spam opened case I will report to support in next days if update fix spam issues or not(But probably it will be same)...

  • Hi,

    I have found that the VoIP handling is not working very well. I have two VoIP service and found that the voice breaks up will listening to the call. I have QoS enabled on the VoiIP services set at 144kb/s. The maximum traffic on the VoIP calls is about 80kb/s  on one service and about 30kb/s on the other. My internet connection is 50/18 (54/18.5).

    This was not issue on previous versions.

    I find the breaks in the conversations very disconcerting.

    Ian

  • I can confirm LuCarToni's workaround. I had the same problem after upgrading from 18.5.2 to 19.0.1.
    I put the access points (without Central Wireless) into several VLANs and so far I have no more problems. It is of course a little effort to provide the active components (switches) with the VLANs, but are with us and our customers all managed switches Relaxed
    And I have also gained more flexibility, because I can now determine exactly in which directions the data traffic between the WLANs and the LANs should run.

    Best regards

    Michael

  • Hi rfcat_vk,

    I am Sanket Shah from Sophos engineering side.

    I have requested few questions on private message.

    Regards,

    Sanket Shah