Hey AlanT,
Hope you can update us on the future of v17 and future of v18?
Since v17 is released i'm sure alot of new improvements are in the pipeline.
This thread was automatically locked due to age.
Hey AlanT,
Hope you can update us on the future of v17 and future of v18?
Since v17 is released i'm sure alot of new improvements are in the pipeline.
By the way, the published set of new features for the next XG 17.5.x, probably in April 2019 since it is schedule in March 2019, is "better centralized Backups" ...
Other than that, I see nothing of any interest this year mentioned anywhere.
Paul Jr
Have you tried the SG product line (aka UTM)? Its much better than XG (IMHO). I recently switched a customer from SG to XG and let me tell you, its been a painful transition. (The reason for the switch was the integration between Intercept X and the XG firewall.)
Your right about DHCP and NTP, and don't forget about trying to make sense of the log files, either from the GUI or the command line... My biggest complaint about XG is the logging.
That and the damn CSS (or whatever) that limits the width of the "viewing portal" on the web pages...
One last thing, SG supports getting certificates from Let's Encrypt automatically. That means no more forgetting to renew and upload/install/waste 10s of minutes on a certificate. I'm not sure what is worse, trying to remember what to do with certificate(s) and private key(s) after 1 or more years, or having to do it every 90 days or less...
Almost forgot about the ability to search the interface that SG has...
I will to get off my soapbox now.
But, Symantec, seriously? I honestly think your better off with Windows Defender. I mean, lets face it, who has a more vested interest in protecting Windows than Microsoft?
To be honest, Sophos AV is the only 3rd party AV product I feel comfortable recommending anymore. I only sell Sophos products because I understand what it is that they are trying to do and I believe that they are doing it well, (OK, XG has a long way to go...) and they are doing things that no one else is doing (at least I'm not aware of any other company doing it...)
Maybe your unaware of Symantec's follies somewhat recently?
https://www.zdnet.com/article/symantec-antivirus-product-bugs-as-bad-as-they-get/
From above link: "...they were using code derived from open source libraries like libmspack and unrarsrc, but hadn't updated them in at least seven years."
Meaning that the exploit was available for at least 7 years before 2016. True it was a while ago, but seriously? How about them as a Certificate Authority?
SG have become technically outdated. No IKEv2 is more than enough to turn around. BTW, IKEv3 is knocking at the door ... Took me 18 months to migrate to XG. I read your pain.
Let's talk about Symantec. I know about what ZDNET posted in 2016. But, I do not base my judgement only on "isolated" bad news. I'm concerned mostly on consistency over the years. Symantec had a very serious performance problem around 10 years ago. But that is resolved.
One of many sites I consult, showing some results. https://www.av-test.org/en/, https://www.av-comparatives.org/, et.c. Some players are almost always 100% catch rate. F-Secure, Bitdefender, Symantec, and Trend Micro. Karpersky had some glitches last year, but are on top almost always. What I do, I compile statistics for two, or three years. When I can. On many web sites. I focus first on protection. Then on performance. Since four products are always there, I select one of them. When I bought Sophos, it was there. Early 2017. But then it felt drastically at the end of 2017. Based on my selection arguments, consistency over the years, I would not select Sophos or Kaspersky today.
One can think what he wants on Symantec, when many experts - which I consider i'm not - reports it is on the top 4 every single years ...
That said, according to my own arguments, I should select Bitdefender. But since I have been using Symantec for so long, I found the little extra from Bitdefender is not worth the extra hassle.
Paul Jr
I am in the same situation with regards to Sophos and what to choose. I have an XG Firewall (Love / Hate relationship) and use Webroot AV.
The Webroot expires soon and I was considering a change to Sophos but I cannot justify the additional spend and not many people speak good of it. So do I want all my eggs in that basket or branch out and look at others such as Crowdstrike, ESET or remain with Webroot.
The clock is ticking.... hmmmmm
V18 will go EAP in July, v18 is expected to ship late this year best case and early Q1 next year in the worst case.
Emile
Common sense dictates you take XG for what it does right now, and do not expect anything new in a predictable future. Meaning, if XG cannot do what you need right now, use something else 3 or 4 years, and check XG again only then. Ironing bugs in v18 will take 3 years. Much like v16/v17 - one and the same - which is clearly not ironed yet.
I'm more convinced than ever Sophos should scrap XG altogether and pimp up everyone's favorite: UTM.
Paul Jr