This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Release of v17 MR-2?

Hej,

now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.



This thread was automatically locked due to age.
Parents
  • I'm super annoyed by MR1 and MR2. Every since I upgraded firewalls from GA release to those, we've had nothing but issues with VPNs disconnecting or not connecting at all. Worked with Sophos Support, but no resolution at all. Instead I'm being asked to have the other side look at their end... great help! I'm dealing with vendors that are not the easiest people to work with that I can just call up like "hey check our VPN and tell me what you see in the logs". The fact that the firmware update started this clearly shows there's something wrong on the XG side, not the other end.

    This needs to be addresses ASAP.

    I recommend NOT UPGRADING TO MR1 or MR2. Stick with V17 GA or anything older.

  • Hi Bjoern, do you have any IKEv2 tunnels in place on 17GA and if so are they stable?

    I too am extremely frustrated with this as most other firewalls have had IKEv2 for some time and don't have these ridiculous issues. I finally got my tunnel to Azure relatively stable and figured I'd update to MR2 and I'm back to the tunnel falling apart when it tries to rekey. 

    Starting to feel like we'll be babysitting these things forever waiting for the "next release" of firmware.

    FIX THIS PLEASE!!!

  • Unfortunately, I don't have any IKEv2 tunnels yet. So many people are way behind on the VPN settings they use and that's why I haven't been able to implement that yet on the VPNs I manage and the firewalls that are on v17 with the described issues. Sorry to be no help in that case.

  • Btw. I set up an IKEv2 tunnel between two XGs the other day and it was working fine for days. I eventually deleted it since I wasn't using it.

  • Thanks for the update. I have still been having some ipsec weirdness and am wondering if it will get to where I can trust it to be stable. I updated to MR-3 and it de-stabilized the tunnel again. I completely removed it and re-created it and it looks good. Unsure if I'll have to reconfigure every time there's an update.

    XG to XG I think would be easier since it's easier to control the ike parameters. Connecting to Azure, AWS, etc. where you can't control the ipsec and ike parameters as well is where I've run into issues.

    One solution for this would be to create a new vnet and create an XG virtual appliance to put the VM's behind - but there's significant effort overhauling your entire cloud infrastructure.

Reply
  • Thanks for the update. I have still been having some ipsec weirdness and am wondering if it will get to where I can trust it to be stable. I updated to MR-3 and it de-stabilized the tunnel again. I completely removed it and re-created it and it looks good. Unsure if I'll have to reconfigure every time there's an update.

    XG to XG I think would be easier since it's easier to control the ike parameters. Connecting to Azure, AWS, etc. where you can't control the ipsec and ike parameters as well is where I've run into issues.

    One solution for this would be to create a new vnet and create an XG virtual appliance to put the VM's behind - but there's significant effort overhauling your entire cloud infrastructure.

Children
  • I'm still seeing some weirdness on MR-3 as well.  It's definitely gotten better (we're about 95% of the way to a good connection),  but I still see some weirdness with the IPSEC SA's not re-establishing themselves from time to time (I'm getting "ALERT: received IKE message with invalid SPI"  occasionally)

     

    In our case we're trying to  run ipsec vpn between Sophos (has dsl connection(pppoe))  through a gre tunnel to a Cisco Router.   Ugh....

     

    -Scott

  • Yeah I get those and retransmission timeouts. Funny part is the only reason I jumped to v17 was for the IKEv2 support. Tunnel was working great on v16 with IKEv1. IKEv2 is needed for having failover tunnels with dual WAN links - haven't been able to set that up yet with all the troubleshooting of basic VPN connectivity :(

    Just keep swimming...Just keep swimming...

  • Hi all

    I have exactly the same troubles with v17 mrX.

    I have several xg linking by IPsec vpn through pppoe xDSL connexions. Everything works great in v16.5 mr8.

    When I update to v17, everything is broken, pppoe connexions never goes up, and/or IPsec vpn never goes up too.

    I precise that I have deleted everything and recreate from scratch.

    A downgrade to v16.5 mr8 and everything restarted well. I am fed up with those crappy v17 mrbeta.

  • Hey, I haven't done a downgrade but from what I gather I just need to upload the version 16 firmware and tell it to boot off of that correct? Is anything lost with the config?

  • so better to be safe with SFOS 16.05.8 MR-8, as the 17 still not stable, I was going today to update HW-SFOS_17.0.2_MR-2.SF300-116 but it seems still too many people complain about un stability 

  • My device recently came with 17 MR-3 and I tried for many weeks, and tons of hours trying to get Ikev1 to work with another companies Cisco ASA which doesn't have Ikev2. Worked with sophos support etc, and they helped me to get it sort of up. But after a restart, it wouldn't come back up or did but flakey. I tried recreating policies and sometimes that only worked for a few minutes, hours or days. I couldn't run my customer's network on that. I gave in, as I was pretty close to calling it quits with Sophos and just getting a Meraki, but on the last night, as soon as I installed 16.05.8 MR-8 from mysophos, tunnel came right up with no fuss. So far 2 days going strong.

  • Ryan,

    yes i would advise you to downgrade to v16.5 mr8 which running very fine !

    Be carreful when you downgrade, you will have to reconfigure everything from scratch. but this will works.

    I can confirm i am totally happy with v16.5 mr8, in many scenarios (IPSEC, multiwan, ssl client or site to site...) and i am actually a bit SAD about v17, now in its 4th "stable" release, and still not stable at all.

  • Totally agree with you, I'm very disappointed with V17

  • When I did downgrade, I was thinking that I'd be able to restore the backup config onto the old firmware, but alas it didn't work. Luckily my configuration is still pretty basic. You might get away with doing an Export/Import instead of the "full config"? But this I don't know for sure. Take a lot of screenshots etc. but also, you can always go back to your 17.x firmware and config with a click as long as you don't overwrite that one on the disk.