Restricted Advance Shell - examples of challenges

Hi Community contributors,

Starting Sophos Firewall v19, with the addition of many comprehensive logging enhancements in the GUI, and in-line with industry best-practices, access to the Advance Shell is restricted to licensed commercial versions of the product.

Partners and certified architect engineers have an option with Not-for-Resale license to set up labs or customer PoC with unrestricted advanced shell. Also, Sophos Support is able access the Advanced Shell via support access channel. Hence, in case of critical issues, support can still can access it.

Sophos Firewall has been incrementally improved since v18 with comprehensive logging enhancements in the GUI (Better search, filtering, configurations, SD-WAN logs, VPN logs, gateway logs etc). However, we acknowledge that Advance Shell restriction might have created challenges in certain database related configurations, especially for home users.

Please help us understand the specific examples of challenges you face due to this restriction - configurations where GUI and console tools are reaching the limits. We will suggest the possible workaround for the specific scenario. We will also plan and gradually improve the product for those scenario.

Sincerely,

Sophos Firewall Product Team

Parents
  • I have an issue with the loss of the Advanced Shell as a home user.  I have an older Atom C2550 acting as a home firewall connected to gigabit fiber.  The default software install on that hardware pins IRQ requests for all NICs to a single CPU.  This causes significant CPU contention issues with a connection that fast, I have to adjust the IRQ assignment after boot to address that issue.

    This change means that as a valid home user, I either need new hardware or another firewall due to the sub-optimal defaults in software installs.

Reply
  • I have an issue with the loss of the Advanced Shell as a home user.  I have an older Atom C2550 acting as a home firewall connected to gigabit fiber.  The default software install on that hardware pins IRQ requests for all NICs to a single CPU.  This causes significant CPU contention issues with a connection that fast, I have to adjust the IRQ assignment after boot to address that issue.

    This change means that as a valid home user, I either need new hardware or another firewall due to the sub-optimal defaults in software installs.

Children
No Data