This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Release of v17 MR-2?

Hej,

now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.



This thread was automatically locked due to age.
Parents
  • Hi everyone,

    MR-2 release is tentatively on December 5th. This can change with unforeseen circumstance, but we'll update this thread if that is the case.

    We'll also post a Discussion post with Release Notes on the Community once its live.

    Cheers,
    Karlos

  • Hi Karlos

     

    Is there a list of for fixes or release notes for what is coming with 17 MR-2?

     

    thanks

  • Hej,

    can I update directly from v16.5 MR-8 to v17 MR-2?

    Thanks.

  • Rodrigo Pereira said:
    NC-19881 [Mail Proxy] Whitelist and blacklist for e-mail/domains in WebAdmin.

     

    Are we sure this made it into MR2?

    I have a test VM that I keep up to date to check on the progress of XG in hopes that I can migrate my UTM 9.x system soon and I do not see this anywhere. I also looked at a hardware install that I have of XG and can not find any sign of whitelist/blacklist management from both WebAdmin and User Portal. If I am looking in the wrong place please point me to where it can be found. Also there is no mention of how this was implemented. I am hoping it is like it is done in UTM to where it can be done either at the administrative level or the end user can maintain the blacklist/whitelist from the user portal.

    This is one of the features that are holding me back from migrating to XG from UTM 9.x

    All systems mentioned above are Home licensed installs.

    TIA

    -Ron

  • Not sure if it makes a difference in Home licence, but my home xg105w now has more options in general settings in MTA mode....

     

     

    So its there, but hopefully it works. :-)

     

    EDIT - Just did a quick check with the block list, and it works fine. To block (and probably whitelist) you can enter the individual address, or wildcard "*@domain.com"

  • Interestingly...I'm only seeing this problem(problem using manually created encryption policy) on one XG135.  I have another one that does not have this issue, but it doesnt have an active VPN going  like I did on the first one.  Going through the creation process on the second unit I can choose a manually created ipsec/encryption policy.    I've opened up a support ticket, hopefully they can give me an answer.

     

  • Thank you for taking a look. So it looks like it is only at the admin level.  What a shame that they did not create it to be at the user level via the User Portal like it is in UTM 9.X

  • rrosson said:
    Rodrigo Pereira
    NC-19881 [Mail Proxy] Whitelist and blacklist for e-mail/domains in WebAdmin. 

    Are we sure this made it into MR2?

    Hi Ron,

    according to the internal ticket system it made it into MR2. I'd suggest having a testrun/testsetup to be sure it matches your expectations.

    Best Regards,

    Afschin

    • NC-22793 [IPsec] Cisco VPN connection with cert auth not working on iOS using config from userportal.

    i still have issues with this wondering whether someone else can test it to make sure not something i am doing wrong.

  • Hej,

    IPSec VPNs are working again. So far, I've only discovered one thing wrong:

    • Self-defined IKEv1 policies are not selectable in Gateway Type" Responde Only

    Does anyone else have the same problem?

  • Hi Steppenwolf,

    i tried to explain current situations in some previous post. Hope this clarifies it a little.

    https://community.sophos.com/products/xg-firewall/f/sophos-xg-firewall-general-discussion/98067/release-of-v17-mr-2/358149#358149

    Kind Regards,

    Afschhin

  • Hej Afschin,

    thanks for your info. One setting of the policy was the problem. For me it was the setting "When Peer Unreachable". I set it to Disconnet and the policy was visible in "Respond Only" connections.

    However, I still have problems with IPSec VPN connections with the "Authentication Type" "RSA Keys". Following message appears after some time in the charon.log:

    INFORMATIONAL_V1 request with message ID 3198824668 processing failed

    Afterwards I can't edit, delete, activate or deactivate the connections with RSA keys via the WebAdmin. Only a restart of the VPN service making them working again.

     

Reply
  • Hej Afschin,

    thanks for your info. One setting of the policy was the problem. For me it was the setting "When Peer Unreachable". I set it to Disconnet and the policy was visible in "Respond Only" connections.

    However, I still have problems with IPSec VPN connections with the "Authentication Type" "RSA Keys". Following message appears after some time in the charon.log:

    INFORMATIONAL_V1 request with message ID 3198824668 processing failed

    Afterwards I can't edit, delete, activate or deactivate the connections with RSA keys via the WebAdmin. Only a restart of the VPN service making them working again.

     

Children
No Data