This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17 hanging a lot and it's not stable, all my issues fix after return to V16

i have 3 Device XG 125 and yesterday morning i have updated 3 devices to V17 and after 3 hours, a lot of issues happened like the following :

 

1- VPN site to site not connection, from the log it say failed ( no more details in log )

2- suddenly when i try to logon to sophos main page , after enter the username and password, it will not login, even no message password is wrong or any message, it just stuck ( fix by hard restart, then it appear 2 time more then fix by hard restart)

3- it's not responding to SSH, mean i enter username and password and i choose to restart or shutdown but, nothing happened 

4- after restarting then login to firmware page to check the current version, it will stuck and nothing appear

 

 

all of this issues appear in all of my XG ( 3 devices in 3 different location ), and all working back normally after back again to firmware 16, so is 17 tested or not ? i'm always doing update for the new firmware and no issue at all, this the 1st time, and this effect my organization for 2 hours, 

 

and can any one advice me the following :

1- is there any support hotline of sophos in UAE?

2- what is benefit of having Enhanced Support, and what different between it and Enhanced plus Support ?

3- what is the backup solution you can advice if one device (hardware or software failed ) ?

 



This thread was automatically locked due to age.
Parents
  • Hi Guys i have this from Support Staff Team,

    please Convert it, in the google translator.

    It means that the Appliance is working well but it disconnects from WAN and from CFM, also we cant logon to the WebAdmin or Userportal, we have to restart over SSH.

    Problem Description:

    Hallo, 
    wir haben erneute Probleme mit einer XG105, die Appliance läuft Fehlerfrei, außer dass man auf keine Oberfläche mehr kommt. Ob WebAdmin oder Userportal. 
    SFOS 17.1.1 MR 1 war derzeit installiert, heute Upgrade ich auf 17.1.2 MR 2. (After Upgrade Same Issue)

    Wir müssen die Appliance dann über SSH neustarten, es werden keine LOGs geschrieben, sodass für mich keine Analyse möglich ist. 
    Die Appliance trennt sich auch vom SFM für mein Partnerportal

    ANSWER FROM SUPPORT AFTER FEW ANALYZES

    Sehr geehrter Herr XXXXX, 

    der Case liegt aktuell im Second Level Support zur weiteren Bearbeitung. Da wir aktuell einige ähnliche Fälle 
    verzeichnen, ist ein Problem in der Firmware nicht auszuschließen. (a problem in the Firmware cannot be rules out)


    Dies muss jedoch durch eine höhere Support Instanz verifiziert werden, bevor wir die ggf. die Hardware 
    austauschen oder das Problem durch ein Update lösen. 

    Mit freundlichen Grüßen, 

    Sophos Technischer Support

     

    Regards N33dfull

  • I have upgraded to 17  latest version but still not able to establish the connection at all between 3 branches (all 3 branches I have upgraded to 17), as per advice, I have rebuilt VPN from scratch with default IKEv2 profile, but still failed, Sophos support logged with me for 30 min but they failed also to establish the connection, so I returned back to 16 and it's very stable, the plan now to try again tomorrow with downtime of  hours to test it with support online 

  • In my case, I had Cisco routers RV325 (with latest firmware) between XG firewalls and ISPs (Internet Service Provider).  Our other firewalls did not have any problems with these routers (Checkpoint, PFSense, ET.c.) but XG could not work with it.  In my laboratory, XG to Cisco to Cisco to XG would work.  But at the moment I would connect Cisco Routers to the ISP, VPNs would fall every ten minutes.  What is puzzling is that both XG AND PFSense uses Strongswane Open Source VPN.

    Maybe you will have to change your routers ...

    Paul Jr

Reply
  • In my case, I had Cisco routers RV325 (with latest firmware) between XG firewalls and ISPs (Internet Service Provider).  Our other firewalls did not have any problems with these routers (Checkpoint, PFSense, ET.c.) but XG could not work with it.  In my laboratory, XG to Cisco to Cisco to XG would work.  But at the moment I would connect Cisco Routers to the ISP, VPNs would fall every ten minutes.  What is puzzling is that both XG AND PFSense uses Strongswane Open Source VPN.

    Maybe you will have to change your routers ...

    Paul Jr

Children
No Data