Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFM - I built one

I built one on my VMware esxi6.x system. An interesting afternoons fun. The registration was about as much fun as registering an XG, not much fun. Activated and that was it, no more internet. Used the same trick of opening up the mac book pro second connection and setting the basic connection to point at the XG gateway.

Next trick, the OVF comes with 4 NICs, not sure why. Any way removed two from the VM configuration, but 4 still show in the SFM and cannot be highlited/marked for deletion even after an SFM restart.

Having to identify each device before it can bo connected is sort of old world or just plain lazy in the design when the utm allows for devices to call home.

Allowing inter device communication on port 80. Not being able to disable port 80 for management access, again another either lazy or thoughtless design for something that wants to be a big business security device.


My 10c worth so far.



This thread was automatically locked due to age.
Parents Reply Children
  • Hi folks,

    following some prompting from Luk I did a detailed investigation of my SFM.

    1/. VM tools not running or not supported. eventually changed state to unsupported

    2/. Reason why my XG originally registered was I had two interfaces operational.

    3/. after registration I disabled the 2nd interface on the UTM even though the selected interface had the correct gateway it still goes out the initial interface (confused so you should be)

    4/. Unable to edit the VM to remove an interface, fails. can change interface but not delete

    5/. the SFM does its own NAT between interfaces which I cannot find a way of disabling.

    6/. cannot delete interfaces or disable interfaces in the SFM and all must have IP addresses assigned.

    7/. no logging of the SFM,the only way to see what is happening is through the console and tcpdump.

    8/. vmtools not being supported means no control of the vmguest from the Vconsole. The SFM never shutsdown found away to trick,, suspend then power  off.

    I will re-address some of the interfaces and see if that makes the SFM receive traffic. no affect

    My real world experience so far.

    edit - added extra information

  • Ian,

    you article make me cry! This is strange that soon I will move to XG and SFM and the product is not ready yet. The trueth is that you are trying it with no support and not enough documentation online. Even on the Sophos Partner Portal, there is no SFM course yet and the SFM product is never touched inside XG Architect course.

    My hopeness is to see many improvements on XG v16 and better documentation of SFM. I tried SFM at home on Vmware Workstation and it looks great and finally a  really product for MSP to manage XGs.

    Hope you will receive better support from community or maybe some clarifications from whom has already tried the product. I am sure that someone is using XG in production already but maybe they do not even know that this community exist.

    May Sachin or other Sophos's staff will reply and help you. For a while I am not able to test the XG and SFM together across internet, otherwise I had already shared my experience.

  • This report might not seem logical to which I agree.

    1/. the UTM cannot see the SFM, tracert show no result, could be becasue there is no real network configuration functions in the SFM to allow for ping or other network debugging tools

    2/. the SFM can be accessed from the same LAN as the SUM and other devices are connected to.

    3/. I have swapped interface addresses and connections in the VM

    4/. the SFM can access the internet and download updates

    So, conclusion is there is some sort of firewall in the SFM which I cannot access or disable.

  • Hi folks,

    Luk spent a number of hours late last night my time investigating the issues I am having with SFM. Thank you Luk.

    Conclusion - XG Mr2 and SFM do not work together. Mind you the issue I had started before I upgraded to MR2.

    Luk has started another thread asking for updates to SFM.

    I will close this thread, disable central management on my XG and powerdown the SFM.