This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall in failsafe mode

Hi to all,

I have two devices in HA... Yesterday, doing some tests, I did be able to see that the passive device is in failsafe mode. If I do a "show failure-reason" command, the device tells me "Unable to apply Firewall Framework"...

How could I recover this device??? This device is new (I bought them about two weeks ago), is it normal???

Thanks to all!!

Regards,

David.



This thread was automatically locked due to age.
Parents
  • David,

    are you using Sophos appliances or intel x86 hw?

    The best way is to remove the HA, format the secondary unit and join it again inside the cluster.

    Regards,

  • Hi Luk,

    I'm using sophos appliances... How can I remove the HA format???

    I have reset the device to the default configuration and the device initialize in failsafe mode too. Have I to do something more???

    Thanks in advance!!

    Regards,

    David.

  • Hi David,

    Select option 2. Reset to factory defaults >3. Reset configuration, report and signatures. This will reset the appliance to factory default settings.

    Refer the below link to disable HA.

    https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Pocket%20Guides/DisableHighAvailabilityHA.pdf?la=en

    Thanks

  • Hi Saching,

    I can't follow this guide beacuse the device doesn't show me the menu... It only shows me the failsafe mode menu:

    Sophos Firmware Version SFOS 16.01.2

    Failsafe Mode

    1. Device Console
    2. Reset to Factory Defaults
    3. Flush Device Reports
    4. Remove Firewall Rules
    5. Advanced Shell
    6. Shutdown/Reboot Device
    0. Exit

    Select Menu Number [0-6]:

    Can I do something from this menu??? The device doesn't let me access it via admin console neither....

    Thanks in advance!!

    Regards,

    David.

  • Hi David,

    Go to Device console and type : system ha disable.

    This will disable HA and the appliance in Auxiliary mode shall restart to factory default. Restart the primary device to boot up in normal mode.

    Thanks

  • Hi Saching,

    as I said to you, this menu is not the normal menu, is the failsafe mode menu... If I select the option 1, the console doesn't let me run this command. I only can run this:

    Sophos Firmware Version SFOS 16.01.2

    failsafe> system
    system System Configuration
    Press <TAB> for see more options
    failsafe> system
    diagnostics Diagnose the Appliance
    failsafe> system

    If I run the system command and I press TAB, it only let me do this:

    failsafe> system diagnostics
    utilities Utilities to Diagnose the Appliance
    failsafe> system diagnostics utilities
    ping Send ICMP ECHO_REQUEST packets to network hosts
    ping6 Send ICMPv6 ECHO_REQUEST packets to network hosts
    ip IP utility from iproute2 package.
    traceroute Print the route packets take to network host
    dnslookup Query internet domain name servers for hostname resolving
    bandwidth-monitor Monitors Bandwidth
    traceroute6 Print the route packets take to network host
    dnslookup6 Query internet domain name servers for hostname resolving
    ip6 IPv6 utility from iproute2 package.
    failsafe> system diagnostics utilities

    Any idea more???

    Thanks in advance.

    Regards,

    David.

     

     

     

Reply
  • Hi Saching,

    as I said to you, this menu is not the normal menu, is the failsafe mode menu... If I select the option 1, the console doesn't let me run this command. I only can run this:

    Sophos Firmware Version SFOS 16.01.2

    failsafe> system
    system System Configuration
    Press <TAB> for see more options
    failsafe> system
    diagnostics Diagnose the Appliance
    failsafe> system

    If I run the system command and I press TAB, it only let me do this:

    failsafe> system diagnostics
    utilities Utilities to Diagnose the Appliance
    failsafe> system diagnostics utilities
    ping Send ICMP ECHO_REQUEST packets to network hosts
    ping6 Send ICMPv6 ECHO_REQUEST packets to network hosts
    ip IP utility from iproute2 package.
    traceroute Print the route packets take to network host
    dnslookup Query internet domain name servers for hostname resolving
    bandwidth-monitor Monitors Bandwidth
    traceroute6 Print the route packets take to network host
    dnslookup6 Query internet domain name servers for hostname resolving
    ip6 IPv6 utility from iproute2 package.
    failsafe> system diagnostics utilities

    Any idea more???

    Thanks in advance.

    Regards,

    David.

     

     

     

Children