Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
SFOS v19 Early Access Program (Read Only)
  • Sophos Firewall
SFOS v19 Early Access Program (Read Only)
Discussions Sophos Firewall: v19.0 EAP2: Feedback and experiences
  • Announcements
  • Discussions
  • Recommended Reads
  • Files
  • More
  • Cancel
  • New
Thread Info
  • State Suggested Answer
  • +1 person also asked this people also asked this
  • Replies 68 replies
  • Answers 1 answer
  • Subscribers 20 subscribers
  • Views 11042 views
  • Users 0 members are here
  • v19
  • sfos
  • EAP
  • EAP2
Options
  • RSS
  • More
  • Cancel
Suggested

Sophos Firewall: v19.0 EAP2: Feedback and experiences

LuCar Toni
LuCar Toni over 3 years ago

Release Post: https://community.sophos.com/sophos-xg-firewall/sfos-v19-early-access-program/b/announcements/posts/sophos-firewall-os-v19-eap-2-now-available

Old EAP1 post: https://community.sophos.com/sophos-xg-firewall/sfos-v19-early-access-program/f/discussions/131583/sophos-firewall-v19-0-eap1-feedback-and-experiences

Release Notes: https://community.sophos.com/sophos-xg-firewall/sfos-v19-early-access-program/b/announcements/posts/sophos-firewall-v19-xstream-sd-wan

If you occur an potential Bug: Please raise a ticket with the "Feedback" Option in the V19.0 Webadmin! 



Paste error.
[bearbeitet von: LuCar Toni um 9:09 PM (GMT -8) am 5 Feb 2022]
  • Sign in to reply
  • Cancel

Top Replies

  • David Tschan - Dreikom AG
    David Tschan - Dreikom AG over 3 years ago +1
    I updated my SG/XG210 from v19 EAP1 to EAP2 right now...worked flawlessly. But I'm still not able to reconnect my SG/XG210 to Sophos Central like it was with v19 EAP1 already - Error: "temporary error…
  • Jindrich
    0 Jindrich over 3 years ago

    Please enable "Add firewall rule" within one click with uncoupling "Add firewall rule" and DNAT assistant. Nobody uses DNAT assistant and if then there is enough space to place it next to the "Add firewall rule" button. Don't force us for all the firewall rules adding click twice instead of a one!

    I was hoping that this will be fixed in v19.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to Jindrich

    I am actually not able to understand, what you mean. Could you give some screenshots context? 

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • rfcat_vk
    0 rfcat_vk over 3 years ago in reply to LuCar Toni

    I suspect he is talking about the server creation rule which probably should be called WAF creation, rather than DNAT?

    ian

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • Gib GoDesk
    0 Gib GoDesk over 3 years ago

    Sorry for asking this question here, but I'm really excited about v19. I wanted to clear up two doubts.

    In version 19, are we expected to have improvements in SSL VPN, which go beyond the performance improvement?

    Today SSL VPN RA and S2S share the same service and the same range of IPs, separating this would be very good without interrupting the two services.
    Another improvement would be to be able to specify which remote destinations of the ssl vpn connection could be made to the remote server.

    I really like IPsec and I like to see you dedicating a lot to this technology. I use and will use them a lot, but in small companies the ease of configuring and managing SSL is very practical. LOT


    Another thing I wanted to know that would help a lot is having the option to clone a reverse rule. It is very annoying to create a rule from src to dst and then create another inverse one, if there was a click that already creates the rule in reverse, it helps a lot.

    Is this expected in the new version or the next ones?

    Another thing that would help a lot to save clicks would be to be able to change a part of the rule, on the line without having to go in and edit. Example, I want to change the port in the services part. In the line of the rule, if you could click on services and the window to change appears, it would be very fast for our day to day.

    Is this expected in the new version or the next ones?


    Sorry to use this channel for these doubts, but I couldn't find a more effective place for a roadmap to be implemented.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to Gib GoDesk

    You still use SSL VPN for Site to Site? Because from my perspective, this is rather rarely used. Why are you rely on SSLVPN for Site connections? 

    Why do you want to do a "reverse rule"? Stateful firewall will allow the traffic in a stateful manner, if this is the goal? 

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • JasP
    0 JasP over 3 years ago

    LuCar Toni you say in this release "Be aware: V18.5 MR2 is not supported to migrate". Is this a cut and paste error?

    The release notes for EAP2 say "Sophos Firewall OS v19 EAP2 (Build 271) is a fully supported upgrade from v17.5 MR14 and later, v18 MR3 and later and all previous versions of v18.5."  and (I believe) I have successfully upgraded from V18.5 MR2 to EAP2

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to JasP

    My bad. Copy/Pasted the old post and missed to remove this part. 

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • Jindrich
    0 Jindrich over 3 years ago in reply to LuCar Toni

    Here are the screenshots. The same goes for nat. Logically the product is the firewall product, so most of all you will add firewall and nat rules, which it is really inefficient to to that all the time via the submenu. Imagine when you are installing a new firewall and have to create 100 fw rule and 40 NAT rule in average all the time for all firewalls.

    The wave of "Enterprise NAT" rejection during v18 launch is long gone, so you can (should) adjust it now.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • Jindrich
    0 Jindrich over 3 years ago in reply to Jindrich

    Small correction Add NAT rule should obviously open "NEW NAT rule page" - not firewall rule page :-)

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • core_memory
    0 core_memory over 3 years ago in reply to rfcat_vk

    I restored the backup of v18.5 MR2 to v19 EAP2. Then, the "TLS certificate" setting of "SMTP TLS configuration" and "POP and IMAP TLS configuration" was changed to "Default".
    I had to change the "TLS certificate" setting to the original.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
<>

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.