{"id":22316,"date":"2019-04-01T12:00:00","date_gmt":"2019-04-01T11:00:00","guid":{"rendered":"https:\/\/www.avanet.com\/blog\/sophos-firewall-os-sfos-update-v17-5-mr4-released\/"},"modified":"2022-07-22T14:45:43","modified_gmt":"2022-07-22T13:45:43","slug":"sophos-sfos-update-v17-5-mr4-released","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/sophos-sfos-update-v17-5-mr4-released\/","title":{"rendered":"Sophos Firewall OS (SFOS) update v17.5 &#8211; MR4 released"},"content":{"rendered":"\n<p>Sophos has released version 17.5 MR4 for Sophos Firewall OS (SFOS).<\/p>\n\n<p><strong>Note<\/strong>: For more information on upgrading, see the following post: <a href=\"https:\/\/www.avanet.com\/en\/kb\/upgrading-sfos-firmware-on-a-sophos-firewall\/\">Upgrading SFOS firmware to Sophos Firewall<\/a>.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-backup-verschlusselung\">Backup encryption<\/h2>\n\n<p>MR4 brings a feature to the XG that UTM users have known for years. The backups can now be encrypted. With a little effort, it was previously possible to read the admin password from an SFOS backup. Sophos says here that until now the configuration was encrypted with a common password that only Sophos knew. Therefore, in the past, we have tended to advise against sending backups via e-mail or uploading them to an FTP server.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"648\" data-id=\"21484\" src=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-1024x648.jpg\" alt=\"Sophos XG v17.5 MR4 - backup password for firewall configuration\" class=\"wp-image-21484\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-1024x648.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-64x40.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-300x190.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-600x379.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-768x486.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-1536x971.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password-18x12.jpg 18w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-backup-password.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<p>We recommend changing the admin password and creating a secure password so that configuration backups are encrypted in the future. After that, you can send the backups by e-mail or upload them to an FTP server with a clear conscience.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"benachrichtigungen\">Notifications<\/h2>\n\n<p>Email notifications on the XG are currently virtually non-existent. However, Sophos is working to ensure that these are improved in the future. With the new XG Firewall firmware there are now first improvements.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications.jpg\"><img loading=\"lazy\" decoding=\"async\" data-id=\"21485\" src=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-1024x142.jpg\" alt=\"Sophos XG v17.5 MR4 - email notifications\" class=\"wp-image-21485\" width=\"910\" height=\"126\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-1024x142.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-64x9.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-300x41.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-600x83.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-768x106.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-1536x212.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications-18x2.jpg 18w, https:\/\/www.avanet.com\/assets\/sophos-xg-firewall-17-5-mr4-email-notifications.jpg 2048w\" sizes=\"auto, (max-width: 910px) 100vw, 910px\" \/><\/a><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"weitere-kleine-verbesserungen\">Other small improvements<\/h2>\n\n<ul class=\"wp-block-list\"><li>There is now an option to generate the application configuration file from the XG Firewall console and import it into GSuite. You can find it under Authentication &gt; Services &gt; &#8220;Download GSuite App Config&#8221;.<\/li><li>GRE and RED interface support for PIM-SM added.<\/li><li>Support for &#8220;DHE key exchange cipher suites&#8221; with HTTPS scanning.<\/li><\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"fehlerbehebungen\">Bug fixes<\/h2>\n\n<ul class=\"wp-block-list\"><li>NC-28883 [Authentication] Able to change group membership of backend users when authserver doesn&#8217;t exist anymore<\/li><li>NC-38834 [Authentication] access_server service getting restarted due to heartbeat found dead<\/li><li>NC-39735 [Authentication] User under an OU falls under OPEN GROUP upon authentication<\/li><li>NC-40072 [Authentication] Not able to delete surfing quota profile, delete opcode search for accesspolicyid instead of surfingquotapolicyid<\/li><li>NC-40945 [Authentication] Failed and successful logins at the same time<\/li><li>NC-42329 [Authentication] Unable to upgrade from v17.1 MR4 to v17.5 GA<\/li><li>NC-34479 [CSC] Virtual XG randomly rebooting &#8211; snort using up all swap<\/li><li>NC-39990 [DHCP] When statically assigning an IP to a devices on multiple DHCP scopes, the gateway settings are pulled from the first one<\/li><li>NC-34039 [Email] Websites are blocked by Sophos AV because of reason &#8220;Malware&#8221;.<\/li><li>NC-38555 [Email] File Protection can&#8217;t block MIME type doc<\/li><li>NC-38840 [Email] Unable to delete a particular email which was quarantined<\/li><li>NC-40071 [Email] GUI option for offline relate on\/off for inbound mails<\/li><li>NC-40131 [Email] Mail downloaded from error queue doesn&#8217;t get displayed properly in mail client<\/li><li>NC-40364 [Email] Personal email exception manipulation by other authenticated users<\/li><li>NC-40389 [Email] Mails released from spool get an incorrect firewall rule ID<\/li><li>NC-40666 [Email] Coredump in mailscanner<\/li><li>NC-41061 [Email] SPX encryption leads to &#8220;carriage return and line feed&#8221; in attachments<\/li><li>NC-41574 [Email] SPF should get applied on inbound mail sent from protected domain to protected domain from internet<\/li><li>NC-41862 [Email] Mail log on GUI does not show delivered mails<\/li><li>NC-42409 [Email] Bounce back mail due to recipients having MX records which point directly to an IP<\/li><li>NC-43353 [Email] smtpd behavior is different from 17.1 to 17.5 (without subscription)<\/li><li>NC-43703 [Email] Warren service unable to load EC type CA certificate.<\/li><li>NC-35350 [Firewall] PPPoE interface status remains in status &#8220;Connecting&#8221; for 2 hours<\/li><li>NC-39522 [Firewall] Network protection options in setup wizard of XG are misleading<\/li><li>NC-39605 [Firewall] Modifying one time schedules fails, if timer has already triggered<\/li><li>NC-39907 [Firewall] API command to enable SpoofProtection is not working<\/li><li>NC-40176 [Firewall] Firewall rule is listed in business application rule destination network objects<\/li><li>NC-40622 [Firewall] Incomplete MAC address shown in Log Viewer<\/li><li>NC-41316 [Firewall] Update country host DB<\/li><li>NC-41389 [Firewall] HA &#8211; system doesn&#8217;t send out garp upon failover<\/li><li>NC-41632 [Firewall] Business Rule &#8211; port translation not working as expected<\/li><li>NC-41652 [Firewall] Unable to delete vlan interface &#8211; &#8220;Interface could not be deleted&#8221;.<\/li><li>NC-42342 [Firewall] One time timers are executed before expected time<\/li><li>NC-39813 [FQDN] Unable to use underscore in FQDN host creation<\/li><li>NC-37771 [Hotspot] Duplicate vouchers in export files<\/li><li>NC-38004 [Hotspot] Hotspot password of the day is not getting reflected into run time config<\/li><li>NC-38120 [IPsec] L2TP over IPsec is sending keepalives forever<\/li><li>NC-38746 [IPsec] S2S connection is not initiated after DHCPv6 interface update<\/li><li>NC-39267 [IPsec] IE11: cannot create and update IPsec policy<\/li><li>NC-41299 [IPsec] IPsec SA is updated with incorrect SA information<\/li><li>NC-42099 [IPsec] Sophos Connect Client cannot connect to Sophos Connect Client policy using digital certificates<\/li><li>NC-42290 [Licensing] Additional CPU cores not detected in v17.5 after license upgrade (NC-26328)<\/li><li>NC-40282 [Logging Framework] High CPU usage from garner \/ active.db grows continuously<\/li><li>NC-34323 [RED] HA active-active routing issue over RED S2S tunnel<\/li><li>NC-42159 [RED] Validation of provisioning file failed<\/li><li>NC-40444 [RED_Firmware] Tunnel compression does not work<\/li><li>NC-38899 [Reporting] Scheduled custom mail reports received via email does not show the mail size<\/li><li>NC-40303 [Reporting] Log Viewer is not loading new logs after screen unlock<\/li><li>NC-40983 [Reporting] Follow-up for NC-26459: Reports for &#8220;Traffic Insight&#8221; not shown on dashboard<\/li><li>NC-41788 [Reporting] Unable to upload custom logo<\/li><li>NC-41232 [SecurityHeartbeat] Heartbeat status on XG showing &#8220;at risk&#8221; instead of &#8220;green&#8221;.<\/li><li>NC-36776 [Synchronized App Control] New Apps number doesn&#8217;t match the displayed list entries<\/li><li>NC-37423 [Synchronized App Control] SAC Tab fails to load for high number of EPs and APPs<\/li><li>NC-37815 [UI Framework] Guest User expiration is not correctly ordered<\/li><li>NC-40158 [WAF] Disable TLS session tickets<\/li><li>NC-34088 [Web] Application control shows blocked applications when they are not blocked<\/li><li>NC-38892 [Web] Inappropriate description in web category for &#8220;Society &amp; Culture&#8221;.<\/li><li>NC-39517 [Web] Webfilter memory usage is growing over time and not going down<\/li><li>NC-39817 [Web] Application filtering using &#8220;Smart Filter&#8221; filter disappear randomly<\/li><li>NC-40265 [Web] Unable to run web policy test for generic top level domains<\/li><li>NC-40503 [Web] Web filter policies not getting updated after CR to SFOS migration<\/li><li>NC-42264 [Web] Garner on Aux node dead after upgrade to v17.5<\/li><li>NC-43056 [Web] Policy tester activities shows junk characters in result with file download is blocked<\/li><li>NC-38368 [Wireless] APs randomly going to INACTIVE STATE<\/li><li>NC-38868 [Wireless] Time based scan with DCS is not showing after configuration for 5.0Ghz<\/li><li>NC-39840 [Wireless] Wireless interface going to UNPLUGGED STATE<\/li><li>NC-39986 [Wireless] 5 Ghz band is not available in AP setting while country set to Qatar<\/li><li>NC-40091 [Wireless] Disable TCP Segmentation Offload for separate zone interface<\/li><li>NC-38085 [WWAN] Unable to detect 4G USB Modem D-Link DWM-222 A1 on XG 125 and XG 85 with HW Rev.3<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Sophos has released version 17.5 MR4 for Sophos Firewall OS (SFOS). Note: For more information on upgrading, see the following post: Upgrading SFOS firmware to Sophos Firewall. Backup encryption MR4 brings a feature to the XG that UTM users have known for years. The backups can now be encrypted. With a little effort, it was [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":21299,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[277],"tags":[],"class_list":["post-22316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/22316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=22316"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/22316\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/21299"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=22316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=22316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=22316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}