This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After MR7 , IPS Pattern fails to update 3.13.89

Hi All,

IPS is not updating anymore after MR7. Can someone else confirm this behaviou?

Thanks



This thread was automatically locked due to age.
Parents
  • Hi All,

    Restart the IPS service manually from System Services | Services | IPS and then try "Update Pattern Now" from Back & Firmware | Pattern Updates. Alongside, please DM us the following logs and if anyone has a registered case# with the Support Team. Please refer, Sophos Firewall: Where to find log files.

    1. u2d.log

    2. csc.log 

    3. Start debug log for IPS service before capturing the ips.log

    Thanks

  • Hi,

    restarted and no affect.

    Will capture logs later.

    ian

  • Just to add that Avira and Sophos patterns failed to updated. I restarted the system, and moved the U2DVERSION file to U2DVERSION_old under /content/avira and Avira updated successfully (because a new pattern was available).

    The same trick did not work for savi, because there are no other new pattern. I will try tomorrow.

    Sophos you should provide a way to force the download of the package in some way. Using commands, procedure of whatever. I formatted the XG and the behaviour is the same with pattern update process.

    Something is broken inside MR7.

    Thanks

  • Avira is dated 29/8/2017

    Sophos and ATP are dated 28/8/2017

    IPS is dated 24/8/2017

    Ian

  • Just to inform that Sophos AV pattern is still downloading (from gui) while on /content/savi_new the pattern is updated.

    Sophos AV 1.0.11425

    Strange! I guess we need to wait for v17 beta and move to it in order to fix the issue.

  • Hello luk,

    would not be a solution try to clean installation from ISO file, run the Pattern Updates and after these steps restore a configuration? The ISO MR7 is already available on the MySophos portal.

    It is an idea, I do not know if it will work and if it is an acceptable solution because of reports, logs, etc.

    I have one HW appliance and one vmware appliance and I did not even notice none of the reported problems with one of them (thank God).

    alda

     

  • Alda,

    when I opened this thread, I upgraded XG from MR6 to MR7 because IPS pattern was not updated correctly. Sunday morning I formatted the unit, installed mr7 from ISO and performed the restore config. WAF and Client Authentication are in failed status and even Sophos now.

    I guess that something from Sophos Cloud (from where the updates come from) or maybe something on MR7 is broken.

    Thanks for your advice!

  • Hi All, 

    We were able to check this issue and found that the issue is with the UI and as per the logs we have concluded that the pattern is updated to the latest version. We believe that this issue will be sorted out after the next IPS update. 

    There will be no impact for the customers experiencing this issue and you may ignore the "Failed" status for now until the next update.

    Reference: NC-21583

Reply
  • Hi All, 

    We were able to check this issue and found that the issue is with the UI and as per the logs we have concluded that the pattern is updated to the latest version. We believe that this issue will be sorted out after the next IPS update. 

    There will be no impact for the customers experiencing this issue and you may ignore the "Failed" status for now until the next update.

    Reference: NC-21583

Children