Restricted Advance Shell - examples of challenges

Hi Community contributors,

Starting Sophos Firewall v19, with the addition of many comprehensive logging enhancements in the GUI, and in-line with industry best-practices, access to the Advance Shell is restricted to licensed commercial versions of the product.

Partners and certified architect engineers have an option with Not-for-Resale license to set up labs or customer PoC with unrestricted advanced shell. Also, Sophos Support is able access the Advanced Shell via support access channel. Hence, in case of critical issues, support can still can access it.

Sophos Firewall has been incrementally improved since v18 with comprehensive logging enhancements in the GUI (Better search, filtering, configurations, SD-WAN logs, VPN logs, gateway logs etc). However, we acknowledge that Advance Shell restriction might have created challenges in certain database related configurations, especially for home users.

Please help us understand the specific examples of challenges you face due to this restriction - configurations where GUI and console tools are reaching the limits. We will suggest the possible workaround for the specific scenario. We will also plan and gradually improve the product for those scenario.

Sincerely,

Sophos Firewall Product Team

Parents
  • holy moly, only just found this thread Rofl thought I was the only one disappointed the advanced shell was being removed.

    For me, if we're running Sophos XG at home, we're generally techies and love command line access, well, because we love that kinda thing.

    pings, traceroute, tcpdump, atop, scripting (speed test script i've written), tailing of logs, iftop, ethtool for check interface speed, ifconfig for errors/discards. just to name a few off the top of my head.

    Is my nan going to be running an XG home edition? No, she'll be using her ISP router. But for a techie, Sophos Home has been perfect and also helps build brand loyalty. My fear is you remove this from us techies, an alternative will come along, and we will move to it.

    And before you know it, we're running that at home. And next time our business reviews which firewalls we resell - ohhh let's have a look at the commercials behind product X.

    I know the argument is - use an NFR if you're a partner. Well I've got an NFR, but you're then adding - chase account manager yearly for new NFR, my NFR is for 4Gb of ram and 2 CPUs, so it's actually a downgrade from my home box. They're small things, but let me tell you, humans are lazy. I don't want to add a "chase account manager" every years for new NFR license to my todolist, if a similar product is released that removes this requirement.

    Like others have said, I think it's a mistake, but I also think you're not going to listen, so let the bygones by bygones. And see how your community "grows" in the coming years.

    ------------------------------------------------

    worlds number one free ICMP monitoring platform: https://pinescore.com

Reply
  • holy moly, only just found this thread Rofl thought I was the only one disappointed the advanced shell was being removed.

    For me, if we're running Sophos XG at home, we're generally techies and love command line access, well, because we love that kinda thing.

    pings, traceroute, tcpdump, atop, scripting (speed test script i've written), tailing of logs, iftop, ethtool for check interface speed, ifconfig for errors/discards. just to name a few off the top of my head.

    Is my nan going to be running an XG home edition? No, she'll be using her ISP router. But for a techie, Sophos Home has been perfect and also helps build brand loyalty. My fear is you remove this from us techies, an alternative will come along, and we will move to it.

    And before you know it, we're running that at home. And next time our business reviews which firewalls we resell - ohhh let's have a look at the commercials behind product X.

    I know the argument is - use an NFR if you're a partner. Well I've got an NFR, but you're then adding - chase account manager yearly for new NFR, my NFR is for 4Gb of ram and 2 CPUs, so it's actually a downgrade from my home box. They're small things, but let me tell you, humans are lazy. I don't want to add a "chase account manager" every years for new NFR license to my todolist, if a similar product is released that removes this requirement.

    Like others have said, I think it's a mistake, but I also think you're not going to listen, so let the bygones by bygones. And see how your community "grows" in the coming years.

    ------------------------------------------------

    worlds number one free ICMP monitoring platform: https://pinescore.com

Children
No Data