Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM 9.510-4 released - let's share experiences!

Released yesterday:

https://community.sophos.com/products/unified-threat-management/b/utm-blog/posts/utm-up2date-9-510-released

 

Found out so far, that mailmanager is broken:

Others? :-)



This thread was automatically locked due to age.
Parents Reply Children
  • Sorry, yes, 9.510-5 indeed..... Still no problems so looks good so far. Next weekend most likely going to also upgrade the largest site which also heavily uses mail protection.

  • Still no problems may be a little exaggerated.

     For one of our customers (2500 mailboxes, 1500 mobile devices), we have to move the Sophos cluster 2-3 times a day. We have Exchange behind the WAF and we suspect that the Apache web server cannot process the amount of access. The message 'Scoreboard is full' will appear in the WAF log, and shortly afterwards no Active Sync or Outlook Anywhere access will work. After rebooting the active node, everything works again until the next scoreboard error. This is actually not a very large environment there, but it seems that Sophos is only designed for home use or SMBs.

    We also noticed that UTM does not support load balancing with Exchange 2016, here the Exchange servers have to be flagged as 'hot standby', which works fine with Exchange 2016.

    With Exchange 2013 Load Balancing was no Problem.

    That's why we opened a support ticket about 6 weeks ago, which has escalated to the development department, but so far we haven't received an answer.

    For this reason, we have now routed HTTPS traffic around Sophos directly to Exchange servers and use the UTM only for SMTP spam filtering.

     Hopefully this problem will finally be solved in a future version and load balancing with Exchange 2016 will also work.

  • Raven, you're not the first person to report this here - that started three years ago.  Are you saying that these problems only began after Up2Dating to 9.510-5?

    Have you tried the following?

    cc set reverse_proxy max_threads_per_process 75

    I don't know when that gets reset, but I'd guess that it would possibly be during an Up2Date.  You can check the value with:

    cc get reverse_proxy max_threads_per_process

    I'm surprised that Support didn't try that.

    There's another thread here somewhere where the load-balancing solution for Exchange 2016 is, apparently, a different load-balancing tool.

    Cheers - Bob