Restricted Advance Shell - examples of challenges

Hi Community contributors,

Starting Sophos Firewall v19, with the addition of many comprehensive logging enhancements in the GUI, and in-line with industry best-practices, access to the Advance Shell is restricted to licensed commercial versions of the product.

Partners and certified architect engineers have an option with Not-for-Resale license to set up labs or customer PoC with unrestricted advanced shell. Also, Sophos Support is able access the Advanced Shell via support access channel. Hence, in case of critical issues, support can still can access it.

Sophos Firewall has been incrementally improved since v18 with comprehensive logging enhancements in the GUI (Better search, filtering, configurations, SD-WAN logs, VPN logs, gateway logs etc). However, we acknowledge that Advance Shell restriction might have created challenges in certain database related configurations, especially for home users.

Please help us understand the specific examples of challenges you face due to this restriction - configurations where GUI and console tools are reaching the limits. We will suggest the possible workaround for the specific scenario. We will also plan and gradually improve the product for those scenario.

Sincerely,

Sophos Firewall Product Team

Parents Reply
  • If you believe the cli is blocked so they can update the SFOS cli good luck holding on to that dream. I have been asking for better logging, renaming ports (cosmetically done with v18), consistent kilobits and kilobytes usage, more advanced system graphs that show cpu and memory usage in real time; smart objects like SG where you know exactly where objects are being used anywhere in the system. In XG we get a generic can't delete foo since its being used error and no way to force delete the object. Actual throughput numbers on each interface in real time, NTP server for all the IOT traffic etc. 

Children
  • This is another thing that I am missing through advanced shell. Access to sql DB. With commands, you can easily see where the object to delete is used. Twice, I was not able to delete an object on v18 at home, and the objects were nowhere. At the end, I was able to search for them and delete the corresponding rule and NAT id. They were not in the GUI.

  • This 100%! Useful features, still not implemented after years of "development". The whole "Mail Protection" on XG is a huge mess that led countless times to customer complaints that just can't and/or won't get resolved. When I started using XG instead of UTM some years ago I had hope that it will catch up soon. Today I can say for sure that Sophos has absolutely no interest in it's partners and customers. They don't care what we want, they just do what they want, ignoring the fact that we are the ones selling their messy stuff.

    Looking at this thread alone and realizing how they have their priorities set, I just contacted Fortinet to get a Lab device with license from them.