This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New release MR-3 comments

Hello,

Yesterday my XG Firewall decided to upgrade itself to the new MR-3 release, on a reboot, even if I clicked each time before not to upgrade yet.  After the upgrade, the IPSec Site-to-Site to an OpenWRT router was not working right.  Looking at the logs in the OpenWRT router, I saw that tunnels keep creating themselves, and after seeing hundreds of them, the link between the site was too slow to be workable, I had to revert to MR-2, where this issue is not present.

I am a new user of Sophos.  I was impressed with XG firewall and installed it at my place and at one of my friend, but I was less impressed with the MR-3 release.  How could a bug like this go through?  Anyway, if I can be of any help to find and fix this bug, I'll be glad to help.

Another small bug present in both versions; the notification emails, to tell that the VPN link is down or up, is not always sending an email on a status change, especially when the link is back up.

Best regards,

Dominic



This thread was automatically locked due to age.
Parents
  • Hi Dominic, 

    In order to investigate further, we would need to do further testing while you're on MR-3. Are you able to setup a test environment so that it doesn't affect your live network?

    First, try recreating the IPsec tunnel on MR-3 and see if the issue persists. If so, please provide output of your IPsec VPN logs from the XG for review.

    To confirm, tunnel comes up but traffic does not flow?

    Thanks,
    Karlos

  • I can reproduce easily, and the log on OpenWRT was much easier to follow on what was going on.  Tunnels keep being opened at a fast rate, and when too much tunnels were opened, traffic could not flow anymore (it would be slower and slower), as the routers were just too busy with creating and deleting hundreds of tunnels.

    This behavior is not present with MR2.  I would prefer that you build the test environment, as no one will pay for my time, and I do not want to take personal time on this, I already spent a night without much sleeping on it.  I do not want to put any more time, but I can asnwer any questions you may have.

  • Hi Dominic,

    Unfortunately, we're not able to recreate your environment. We have successful IPsec site-to-site VPN's on MR-3 in test environments, so it seems specific to your setup or configuration. But don't hesitate to reach out again if you would like help troubleshooting this in the future. 

    Cheers,
    Karlos

  • You have tried with an OpenWRT router at the other end?  No one will look into the code to catch this?  I think it should be easy to catch, since it is a change between MR2 and MR3.

    At the end, I do not really care that you fix it, since they are other products competing with yours.  I found Sophos in an article comparing it to PFSense, and the article mentioned it was easier to setup.  I play with routers every day, so I know my way around, but I'm tired fighting with buggy hardware and software all around.

    I have been impressed with the ease of Sophos-XG, but MR3 makes it loose its edge.  I think you have a good potential product, customer support still need some work.  Wish you a great year.

Reply
  • You have tried with an OpenWRT router at the other end?  No one will look into the code to catch this?  I think it should be easy to catch, since it is a change between MR2 and MR3.

    At the end, I do not really care that you fix it, since they are other products competing with yours.  I found Sophos in an article comparing it to PFSense, and the article mentioned it was easier to setup.  I play with routers every day, so I know my way around, but I'm tired fighting with buggy hardware and software all around.

    I have been impressed with the ease of Sophos-XG, but MR3 makes it loose its edge.  I think you have a good potential product, customer support still need some work.  Wish you a great year.

Children