This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I really want to like this product, but...

If I'd purchased this for deployment in my place of work, then I'd be looking for a refund.

1) The webfilter issues are a show stopper. I wanted to use the webfilter to enable malware/antivirus scanning on the gateway. As soon as I enable the webfilter, then Youtube, Netflix, and the kids Amazon Fire TV boxes are all rendered useless. This has been posted about several times, and there is no response.

2) My connections shows interface status up, gateway down, but it's not down. I've tried with a straight and also a crossover cable - no difference. It's working so why is it saying it is down? Must be a bug.

3) How on earth do you get the performance indicator to stay green? I'm running it on ESXi 6 and have given the box 2 cores (and even tried 4) and 6Gb of RAM. Still it's flagging performance as orange.

4) Can't get email notifications to work using my normal Microsoft Exchange hosted server. Notifications from other applications BEHIND the Sophos XG firewall work, so why don't they work from Sophos itself?

5) Support is pretty much non-existent. It just seems to consist of users helping users, and at the moment it's like the blind leading the blind - none of us can figure the product out properly and most of us are not exactly networking novices. That should be telling you something about your product.

Rant over.



This thread was automatically locked due to age.
  • I'll combine your first comment with your #5 first - if you had bought this for your workplace, you'd likely be entitled to support. Support wouldn't be non-existent, and they'd work with you through these issues. I'm working with their support engineers now on a few bugs, and they're excellent. How they should be supporting other folks - like forum folks - that aren't paying XG customers yet - that's a different discussion. I think their involvement here could (should?) be better... especially since they seem to want people to use the free home version... and I think it will get better... Support just got handed a new product, too, so they are working to understand this new XG product as well. Give it a little time.

    Now - 1) webfilter issues. Just about any webfilter with HTTPS filtering is going to break something like netflix and amazon fire. I enabled Watchguard's version of https filtering at my house - had very similar issues. I came from and am certified in the watchguard product, so I had a spare of their smaller boxes lying around to test. Anyway - anything that tried to validate SSL certificates - and for which installing new certificates was nearly impossible - generally had major issues. Amazon Kindle e-readers would freak as well. This is a known issue with just about any deep packet inspection https filter, and the only way resolve that is to install the ca certificate from the firewall onto the end devices - or except the traffic from the https filter. The XG device actually makes it fairly easy to except certain traffic from HTTPS inspection. Entire categories can be exempt via the policy, and when ssl certificates for those sites are detected, the traffic is not intercepted and monkeyed with, or individual IP addresses can be exempt as well. I've found it works acceptably well. I have had to add in a few *special* exemptions - logmein rescue, for example, certain sites using websockets in an odd way, that sort of thing - but overall, it is working like an absolute champ.

    2) can the gateway be pinged? The xg relies on pings - not whether traffic is passing through the interface - to determine the status of the gateway, I believe. I think I remember that from the XG certification course.... Maybe that was only multi-wan was setup...

    3) What's the load average look like on the performance screen?

    4) Do a packet capture on the smtp traffic to see what the SMTP conversation looks like. Could be any NUMBER of things - including user error (hey, it happens... even on a stupid smtp connection. )
  • # 2 - I just had this same issue.  Only thing I could do to get it 'green' was go to the interface, set it to static, back to DHCP and hit save so it refreshed.  IPs stayed the same, nothing changed but on the front page it showed up.  This must just be a bug, the gateway was pingable.

    # 3 - Same here, I'm running on a physical server.. it was green for a while but is orange even though all the graphs and reports show a very low load

    #5 I have had experience with Support on this product and I can say it was outstanding, I couldn't fault it at all. Someone was in constant touch with me via email every day, multiple times a day, sometimes even just to say they were still working on it but they always replied and answered any questions they had.

    Out of all the firewall vendors we've been through, Sophos support (so far) has been the best - even for a free product.

  • Yes, that's what I was getting at - their involvement on this very forum.

    1) Maybe I misundertand the issue with the webfilter then - I don't want to have to mess with certificates. I do want web browsing to be scanned for malware/virus and I have tested with the webfilter switched on and it does indeed detect those things. However, as stated above Netflix etc break with the webfilter on. That means that Video Streaming functionality and malware/virus detection are mutually exclusive at the moment with this product.

    2) I have no idea if it can be pinged - this is the WAN and is not on my LAN - I'll try the below recommendation from Wayne!

    3) Load average has gone above 2 which is what triggers it - however I cannot see why it goes above 2 when cpu usage and RAM usage are negligible. There appears to be no logical correlation.

    4) It seems I am not the only one with this issue now - I'll have to dig further, but the lack of any proper realtime log makes troubleshooting more difficult. Unless I am missing that feature somehow?
  • I tried setting the interface to static and back to DHCP and it refreshed the interface but still shows as down.

    I'd check the modem for whether pings are allowed, except it is a Huawei HG612 and it is locked down - don't really want to have to go putting the hacked firmware on it really.
  • Yeah their involvement should be better here - but again - they have to balance HOW MUCH support they provide to folks using their product for free against supporting paid customers. It will likely get better, given some time. I've seen SOME involvement by their guys here... We will also be able to judge their commitment to a free product by the support response. It may be that they decide they really don't care about the free product. I'd hate to see that - as it can provide valuable feedback and exposure - but we will ultimately "just have to see."

    RE web filtering - Back in the day, everything went over HTTP except for specific bits that *needed* encryption. Now, HTTPS now is on for a lot of websites *by default* for all traffic. HTTPS filtering is something that is not to be done half-way, as it REALLY can, as you've seen, screw with services. It IS complex, but NOT as complex as it sounds. Unfortunately, in order to do more than basic category blocking of HTTPS traffic that doesn't always work thanks to wildcard certs, CDNs & SSL accelerators like Cloudflare, etc, you have to effectively perform a "man in the middle" attack on your own traffic. That means having the XG presenting your clients with a "fake" version of the legitimate website's certificate, and then the XG communicates with the secure website. In order to do that, the XG has created its own CA certificate. You just need to trust that certificate. Some devices can't do that. Most devices can.

    Go here: Protection > Web Protection > Web Content Filter, find HTTPS Scanning CA. See which one is listed. (I can't remember which is the default, and we use a custom CA here)

    Then go here: Objects > Identity > Certificate Authority, find the CA listed above and click the download button on the far right.

    Then, install that onto each computer in the trusted root store. See KB article here: www.sophos.com/.../42153.aspx for instructions. Those instructions are for the web appliance, but starting at the end of #1, it becomes generic.

    To exempt devices from policy, you can either create rules for them based on their IP, or create clientless users here: Objects > Identity > Clientless Users for your other devices and then create one rule exempting the clientless users group from from https filtering. You can also create a separate wireless network on a separate network segment and exempt all of that traffic from scanning - almost like a guest wifi or something. There are options.

    In case you can't tell, I am a *BIG* proponent of HTTPS filtering, and doing anything I can to improve the understanding of HTTPS filtering. It CAN be a pain... but the benefits are excellent and well worth a little bit of setup pain.

    Also - I will say this - XG's HTTPS filtering is about as good as I've found. It beats watchguard's, and a few others.

    Unfortunately, HTTPS filtering for home use is just the other side of "pain in the ass." I still haven't implemented it at home properly yet - for the same reasons you mentioned. It just broke too much stuff "out of the box" and I haven't had time to do it properly yet.

    Good luck!
  • I would like to thank you for taking the time try and explain things to us. I do understand this is a new product in fact its very much v1 as has been said many times in the beta program when I was a part of it that said communication from Sophos even in the beta program was none existent and when a company is asking for are help in testing and asking for our feedback and it falls a dead ears with no response that's never a good thing.

    As for Netflix not working on mobile devices this is something going back to UTM9.x at least in UTM9 we could fix it with some Regex entries and move on with our lives without completely disabling web filter and HTTP scanning, Its not just when HTTPS scanning is enabled its when plane HTTP scanning us used. No matter what we do with different combinations if you have ANY of the following 3 things active it breaks Netflix on mobile devices

    web filter
    HTTP Scanning
    HTTPS Scanning
  • I wish we had access to some of that great support. The home users should have access to at least email support like any other company would give. I understand we would not be priority but a "we will respond with in 72 hours" or whatever is better then nothing. Sophos has to remember free home licenses could turn into paid as many of us would test it home first.
  • I just emailed support@sophos.com and told them it was the Home XG Firewall and they immediately started helping me after the initial response. I don't know if I got lucky or what but I would try that if you haven't already, I had a response within ~24 hours maybe a little longer but for a free product I'm not knocking that.
  • Thanks for the tip. Did you put this is the Home XG Firewall in the subject line or in the body of the email? And I agree cant ask for much better then 24 hours response time, that's great!
  • Ok Just sent an email, I hope I get as lucky as you. Thanks for the tip.