This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After upgrading SG135 to FW 9.711-5 our RED 50 connection is lost.

Hello together,

after upgrading our SG135 from 9.705-5 to 9.711-5 our RED 50 connection is lost.
Status is ON but the Link is OFF. The RED 50 is trying to connect and then the device reboot.
Because I am really new to the Sophos UTMs I've no experience what to do.
So far I can see, there is no way to rollback the upgrades, so the only way is install
an old image on the UTM? Or is there a easier way?

Thanks and best Regards
Martin



This thread was automatically locked due to age.
Parents
  • Hello ,

    Thank you for reaching out to the community, you have delete the red config and add it again, and the check the logs under the /var/logs - red.log !!

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • I found this in the actual log:

    2022:09:29-09:51:44 utm01 red_server[21222]: SELF: Cannot do SSL handshake on socket accept from 'xxx.xxx.xxx.xxx': SSL connect accept failed because of handshake problems
    2022:09:29-09:51:46 utm01 red_server[21223]: SELF: New connection from xxx.xxx.xxx.xxx with ID xxxxxxxxxxx (cipher AES256-GCM-SHA384), rev1<30>Sep 29 09:51:46 red_server[21223]: xxxxxxxxxxxxxxx: Device config was not yet uploaded with the current firmware version '1-501-bb7bd1013-0000000'
    2022:09:29-09:51:46 utm01 red_server[21223]: xxxxxxxxxxx: Connection is refused as device config was not yet uploaded.
    2022:09:29-09:51:46 utm01 red_server[21223]: xxxxxxxxxxx: Sending json message {"data":{},"type":"DEVICE_CONFIG_NOT_YET_UPLOADED_TO_PROV"}

  • Perform under the cli the following: 
    telnet <Public IP connected on the RED> 3400 
    telnet red.astaro.com 3400 
    see if it is able to connect successfully or not ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Reply Children