Release Post: Sophos Firewall OS v19.5 MR1 is Now Available
The old V19.5 GA Thread: Sophos Firewall: v19.5 GA: Feedback and experiences
This thread was automatically locked due to age.
Release Post: Sophos Firewall OS v19.5 MR1 is Now Available
The old V19.5 GA Thread: Sophos Firewall: v19.5 GA: Feedback and experiences
The latest firmware releases removed some alerts, which were in the product. The next alert to be removed is the "Central Managed" alert, which is currently static. All other alerts are removable by "resolving the situation". Deletion/acknolowdiging is something, which requires are complete overhowl of the control center alert system, which is not planned soon.
The removal of "XG" is something valid for future releases. Not planned yet.
Login notification is currently possible for CFR, if you want to get a report per day of who logged in and when. But not for the "instant notification". This is on the backlog.
This has been a very bad experience for us.
Running 2 XGS21000 in HA mode.
Since upgrading connectivity to websites is slow, sometimes hangs completely. Some apps will get disconnected after a few minutes of use. This is consistent so has made those apps useless, for example my General Manager has stopped using Sirius XM radio on his desktop because it will not stay connected. When these problems are happening we see many "invalid packet" in the log file for that client and service. This indicates a problem with nf_conntrack but the only thing support has been able to do for the past few weeks is try adjusting the tcp-est-idle-timeout but the timeouts are already happening much sooner than the timeout value. We will probably roll back soon but if we do that how will we know when it's safe to upgrade again? It is a problem.
This has been a very bad experience for us.
Running 2 XGS21000 in HA mode.
Since upgrading connectivity to websites is slow, sometimes hangs completely. Some apps will get disconnected after a few minutes of use. This is consistent so has made those apps useless, for example my General Manager has stopped using Sirius XM radio on his desktop because it will not stay connected. When these problems are happening we see many "invalid packet" in the log file for that client and service. This indicates a problem with nf_conntrack but the only thing support has been able to do for the past few weeks is try adjusting the tcp-est-idle-timeout but the timeouts are already happening much sooner than the timeout value. We will probably roll back soon but if we do that how will we know when it's safe to upgrade again? It is a problem.
Hello there,
I am sorry to hear about your bad experience.
Can you share the Case ID you have open with Support?
Regards,
Same ticket as mine, 06310523. It's already been escalated. Sent another batch of files to them earlier today and they are reviewing now.
Hello Brandon,
Thank you for the Case ID, I see your case is with an L2, but GES/DEV are interested in looking at this, so I have requested the engineer to escalate it to them.
Regards,