Jump to content

jamesp

Members
  • Posts

    20
  • Joined

  • Last visited

Everything posted by jamesp

  1. Oh I see - I got the wrong end of the stick!
  2. You could do this quite simply with a firewall that has a solid SSL VPN functionality, specifying a full tunnel mode would make all the traffic pass through your infra so you could assign whichever policies you wish. Client side SSL VPN's are usually very easy for a user to set up - a few clicks and a username and password!
  3. Three XG's thus far updated, no issues. Some of my slight VPN S2S issues are gone, looks good to go to people!
  4. Version · SF 17.0 MR2 (17.0.2.116) News · Maintenance Release. Bugs 1. NC-22609 [Access] Unable to import groups inside multiple OUs from AD. 2. NC-19427 [API] Wrong date in validationError.log. 3. NC-22394 [Authentication] User Portal login is logged as SSL VPN login. 4. NC-22769 [Authentication] When importing from AD, the name of OUs which are inherited by multiple OUs and groups is not shown correctly. 5. NC-23112 [Authentication] Authentication Agent - getting logged out automatically at random time. 6. NC-19665 [backup-Restore] Downloading backup creates Java exceptions. 7. NC-21785 [base System] Wizard UI Improvements. 8. NC-22229 [base System] SG115: pressing power off button does not shutdown appliance. 9. NC-22574 [base System] Control center misleadingly shows notification of new firmware availability for few minutes after firmware upgrade. 10.NC-22631 [base System] Typo in fwinstaller. 11.NC-22688 [base System, Certificates] Missing QuoVadis Root Certificate. 12.NC-22771 [base System] Export of 16.5 MR8 and import into v17.0 GA fails for configs without hostname. 13.NC-22780 [base System] Migration from CR to SF failed on CR500ia-10F appliance. 14.NC-22911 [base System] Blank screen is displayed when user synchronizes license after successful registration. 15.NC-25573 [base System] Users cannot activate license keys from SFOS. 16.NC-22354 [Certificates] Passphrase box disappears after trying to upload a CA with private-key after upload fails. 17.NC-22734 [Clientless Access] HTML5 VPN: keyboard input not working on Android devices. 18.NC-22751 [Documentation] Japanese translation for LogViewer missing. 19.NC-17413 [Firewall] Business rules created with device destined IP address can't be blocked with network rules. 20.NC-20602 [Firewall] Incorrect validation for local acl and zone where HTTPS is disabled from current login zone. 21.NC-21180 [Firewall] Add "Action" column to firewall rule grouping. 22.NC-21897 [Firewall] Import/Export of firewall rule with dependent entity fails when a VLAN is configured on WAN. 23.NC-22219 [Firewall] Issue with SNAT policy with multiple gateways. 24.NC-22557 [Firewall] Service edit option not working in specific case. 25.NC-22670 [Firewall] Unable to create RED interface. 26.NC-22923 [Firewall] Hostset ERROR: XG stopped Responding. 27.NC-22932 [Firewall] Export/Import fails for every entity after exporting Security Policy entity. 28.NC-22946 [Firewall] Typo in SF API documentation for IP host object. 29.NC-22958 [Firewall, SFM-SCFM] SFM Compatibility v17: DNAT rule cannot be updated in some combinations of forward type. 30.NC-22982 [Firewall] Incorrect position of firewall rule name in Firefox. 31.NC-22424 [Framework(UI)] Close notification button does not work properly. 32.NC-22917 [Framework(UI)] Information icon does not show any info text in authentication page. 33.NC-21856 [iPS] In AppFilter policy smart filter values are still displayed after removal. 34.NC-22448 [iPS] Custom IPS signature not working for all keyword supported by snort. 35.NC-22753 [iPS] Application filter is not updated when there is no application matching smart filter. 36.NC-22834 [iPS] Application Filter Policy: All application is showing while editing through firewall rule with "selected individual application". 37.NC-22382 [iPsec] IPsec UI allow to configure incompatible policy resulting in a silent DPD action change in the backend. 38.NC-22383 [iPsec] Typo in IPsec policy list: 'Action on Active Peer'. 39.NC-22489 [iPsec] Incorrect IP routes added for local VPN traffic in case of NAT over IPsec. 40.NC-22502 [iPsec] IPsec PSK secrets files do not contain local VPN IP. 41.NC-22620 [iPsec] DGD can not be disabled. 42.NC-22622 [iPsec] 'Remote ID' value shows blank on UI for IPSEC connection when external cert is used. 43.NC-22633 [iPsec] Activate on save tries to connect to respond only connections. 44.NC-22793 [iPsec] Cisco VPN connection with cert auth not working on iOS using config from userportal. 45.NC-22888 [iPsec] IPsec S2S tunnel with PSK and local/remote ids not working. 46.NC-22892 [iPsec] Aggressive mode IPsec policys are not filtered correctly in UI. 47.NC-22900 [iPsec] Cannot create 2 IPsec RSA connections with same local id to different remote gateways. 48.NC-22914 [iPsec] Connection status for DGD IPsec connections is not shown correctly. 49.NC-23035 [iPsec] DGD table locked - postgres has returned errcode 25P02. 50.NC-23125 [iPsec] "Randomize Re-Keying Margin by" - When setting the value to 0%, UI displays 100% after saving the policy. 51.NC-23186 [iPsec] IPsec status not displayed when too many SAs are established. 52.NC-22549 [Logging] Sandstorm logo displayed in RED for reason "eligible","pending" & "Cloud Malicious". 53.NC-22745 [Logging] Port and protocol information are missing in LogViewer standard view and filter. 54.NC-15612 [Mail Proxy] Update DLP engine and CCL data. 55.NC-19881 [Mail Proxy] Whitelist and blacklist for e-mail/domains in WebAdmin. 56.NC-21366 [Mail Proxy] Spam e-mails pass due to error " X-CTCH-Error: Unable to connect local ctasd". 57.NC-21437 [Mail Proxy] Mail addresses with "systems" or "solutions" as top level domain cannot be added in address groups. 58.NC-21671 [Mail Proxy] Message is not displayed properly in LogViewer. 59.NC-21891 [Mail Proxy] Spam headers displayed in e-mail when sent through reply portal. 60.NC-22271 [Mail Proxy] Issues with mails in spool marked with a firewall ID. 61.NC-22921 [Mail Proxy] Email flow is affected for recipients using TLS1.0. 62.NC-25332 [Mail Proxy] awarrenmta service segfaults when IP reputation is enabled. 63.NC-22504 [Network Services] Unable to assign two static IP mappings for the same host in different DHCP scopes. 64.NC-22163 [Networking] OSPF Neighbors not updated on changing multicast group limit. 65.NC-22539 [Networking] Fail to add vlan when specific DHCP server confiration migrated. 66.NC-22662 [Networking] Unable to make changes in WAN Link Manager for an interface with /31 subnet . 67.NC-21952 [RED] Site-to-Site RED tunnel between XG and UTM does not pass traffic with hardware acceleration enabled. 68.NC-22433 [RED] Generating certificates fails when long company name is used. 69.NC-22174 [Reporting] Missing size verification on custom logo for on-box reporting. 70.NC-22819 [Reporting] Application reports stop working after enabling Sync App Control. 71.NC-22853 [Reporting] Drill down is not working in mail report when "Mail Count" is selected as sortby. 72.NC-22868 [Reporting] Font style mismatch. 73.NC-22364 [securityHeartbeat] EP_Certificates table not available error . 74.NC-22778 [securityHeartbeat] Heartbeat registration fails with appliance in HA. 75.NC-22151 [sSLVPN] When using special character in Appliance Certificate, SSL VPN connection fails. 76.NC-22116 [synchronized App Control] Last occurance time of applications in SAC is not consistent between HA nodes. 77.NC-22384 [synchronized App Control] After de-registration of Heartbeat enhancedappctrl service is still running. 78.NC-22440 [synchronized App Control] Sort list of categories in SAC customize menu. 79.NC-22766 [synchronized App Control] Path of a customized app is shortened in SAC customize popup when app path contains slashes. 80.NC-22768 [synchronized App Control] Uncategorized category is shown twice in the SAC customize popup. 81.NC-22813 [synchronized App Control] Fixed height for SAC data table. 82.NC-22824 [synchronized App Control] EP name with special character is not displayed correctly for macOS in SAC list. 83.NC-22962 [synchronized App Control] Show category in SAC app list. 84.NC-22544 [uI] Incorrect start time displayed in Live Users list. 85.NC-22576 [uI] Disclaimer message is shown without line breaks. 86.NC-25275 [uI] Internet usage time displayed "NaN:NaN" value in Live Users list. 87.NC-22319 [WAF] "Edit Reverse Authentication" dialog contains untranslatable strings. 88.NC-22521 [WAF] Leftover of shm files cause a WAF restart loop. 89.NC-21534 [Web] Certificate error on accessing sites with https scanning enabled. 90.NC-21930 [Web] Incorrect Error message on Captive Portal when the user exceeds the number of simultaneous logins. 91.NC-22023 [Web] Word list files with non-UTF8 or whitespace-only should not be uploaded successfully. 92.NC-22124 [Web] Web Policy rule is converted to "AllWebTraffic" when adding more than one backslash character in the rule. 93.NC-22125 [Web] When maximum limit is reached, web exceptions cannot be updated anymore. 94.NC-22403 [Web] Certificate Error while accessing Outlook with direct proxy. 95.NC-22653 [Web] Policy Tester does not display backslash in policy name correctly. 96.NC-22721 [Web] AVD dies unpredictably when it runs out of memory. 97.NC-22800 [Web] AVD stability fixes. 98.NC-22930 [Web] Server side rbuf not reset for reused request. 99.NC-22954 [Web] Access to Custom Captive Portal does not work. 100. NC-23156 [Web] Not able to access any websites due to malformed ATP data update. 101. NC-23163 [Web] Font color for Initial Setup Wizard changes. 102. NC-12089 [Wireless] Unable to edit alias of "GuestAP" interface. 103. NC-19166 [Wireless] SSID disappears randomly with Dynamic Channel Selection. 104. NC-20761 [Wireless] Wireless Client List shows wrong IP address after network change. 105. NC-21369 [Wireless] VLAN and non VLAN SSIDs can't be selected at the same time for RED15w. 106. NC-22358 [Wireless] SSID is not broadcasted from time to time. 107. NC-22852 [Wireless] Wireless network interface status states being unplugged. Some great fixes - I'm patching a load of XG's now - will report any oddities there after
  5. That does not make any sense from a UTM perspective as there isn't anything that would be timing them out so to speak, leave this with me for a bit and I'll have a good think! Out of interest - what AV do you use and are you using anything like Impero or similar?
  6. Interesting, I would take a look in the warehouse folder to see if its current, also I take it you have the required port open to that server (8191 iirc) Oh warehouse is located here: C:\ProgramData\Sophos\UpdateCache\www\warehouse\ If that's all looking right and you still see no computers updating from the cache, have a look at the logs - \UpdateCache\Logs\ Let me know!
  7. Interesting, Cache is something I have not touched in a long time but happy to revisit, usually they just sit there doing their thing!
  8. Look at the XG too - much more user friendly and very robust, UTM's are great though XG in my opinion is what schools should look at especially if your thinking of using Sync Sec
  9. Morning! Pre coffee so excuse the typo's! If your using SSO then you should be ok, the reason that i asked about STAS is that this component has a config for User inactivity - though pure SSO does not, narrowing the issue somewhat. Here's a link to both configurations/setups so you can see technically how they both work: STAS https://community.sophos.com/kb/en-us/126939 SSO (AD) https://community.sophos.com/kb/en-us/120791 Please take a peek, let me know which your using/is set up. Kind regards James
  10. Smells like a user inactivity timeout to me - could you confirm what your settings here, are you not using STAS at all?
  11. Bit more info please When you state resolve - are you talking dns resolution ? Here to help - just feed us more info!
  12. Hi all/OP I would go with Xg for that main reason being the logging and reporting, the customisation is fantastic as is the automation to pump out reports (standard and custom) to others in your org, Daily keyword filterlist hits etc to safeguarding/e-safety officers. Other than that its a one pane firewall thus easy to relate to and administer. I could probably give a demo if it would be useful
  13. It also depends on the initial negotiation - take a look at the link speed and let us know what speed was initially set, its also good to check device drivers as older drivers on newer AP's will neg slower links if not supported. Also check how access is granted out to the WAN - walled garden/client isolation, bridged to LAN and then out usual way or completely separate zone, any policies different wrt Filtering and scanning. fast.com is also a useful site
  14. Hi all, Have been lurking about for a long time on Edugeek though never had much time to post! Luckily I have more time on my hands so will try and help where I can. I'm an Security Architect for many vendors though most up to date with Sophos (UTM, XG, SafeGuard & Central related modules), Checkpoint and SmoothWall, as well mirriad of other vendors.
  15. Old Post I know But I know I'm seeing many Schools currently suffering from broken web filtering due to QUIC, blocking UDP on 443 will force Chrome to drop down to using normal expected packet transit. Just chuck this in your firewall rule as an outgoing rule and you should be golden! If really wanted - you could create a group policy to stop Chrome using QUIC though it would have to be maintained throughout the update lifecycle of chrome. Hope that helps some of you!
  16. I would look at the XG over the UTM now for a Schools environment especially as Synchronised Security can be added at a later date if you intend on getting Sophos AV. UTM is a great box but for Schools - XG ! I Used to Love Love Love! Smoothwall but resent experiences over the last 2 years and the stagnant nature of their development in some respects has tarnished my view on them (obviously my personal view ).
  17. Hi Richard, To be honest the best way to do this would be to create a URL group and then use this in your policy - this way you can create a few specific white lists as well as Block lists. Once created you can use them in your policy and assign Allow/Warn/Block as you would do with a cat. This way its a little more manageable than spinning custom categories and under one tab for visible & quick access. Hope that helps James
  18. Hi James, great shout out! The lockups were indeed patched on the new MR, the IPS engine was running hot on some box's and made them unresponsive, all fixed
  19. Morning all, I'll be starting a "How To" series shortly covering Sophos Products, mainly XG, UTM & Cloud Antivirus. Happy to cover topics you would like also so if you have anything you would like covering in a short video - please do let me know and I'll provide Kind regards James
×
×
  • Create New...