Wednesday, June 11, 2025

Sophos Firewall v21.5 is now out there – Sophos Information

Following a really busy and profitable early entry program, the Sophos Firewall crew is happy to announce that v21.5 is now out there to all licensed Sophos companions and prospects.

This launch brings an industry-first innovation: integrating Community Detection and Response (NDR), which reinforces energetic risk detection in your community.

What’s new overview

Watch this transient video for an summary of the discharge highlights:

Be taught extra

Watch these demo movies for deeper insights into how one can take advantage of the key new options or seek the advice of the earlier sequence of articles on this launch:

Moreover, assessment the What’s New Information, seek the advice of the Launch Notes, or learn on for extra particulars.

Full particulars

An {industry} first innovation: NDR Necessities

Sophos is the primary to combine an NDR resolution with a firewall, additional extending Sophos Firewall’s benefits with XDR and MDR use instances.

We’ve taken the novel strategy of implementing NDR within the Sophos Cloud to dump all evaluation processing from the firewall, eliminating any efficiency hit.

We’re calling this NDR Necessities, and the perfect half is, we’re enabling this for all XGS Sequence firewall prospects who’ve the Xstream Safety license bundle – at no additional cost.

How NDR Necessities works

Sophos Firewall’s XGS Sequence captures meta information from TLS encrypted site visitors and DNS queries and sends that info to NDR Necessities within the Sophos Cloud the place the info is analyzed utilizing a number of AI engines.

It may detect malicious encrypted payloads with out performing TLS decryption. This addresses an enormous blind spot in most organizations the place man-in-the-middle TLS inspection just isn’t getting used for efficiency, usability, or safety causes.

As well as, the NDR Necessities area technology algorithm detects new and suspect domains generated by malware which might be typically a key indicator of compromise. In actual fact, in lots of instances, NDR Necessities can detect new C2 domains earlier than they’re even registered.

The meta information extraction is carried out by a brand new light-weight engine carried out on the Xstream FastPath, and because of this, one caveat with this new functionality is that it is just out there on XGS Sequence {hardware} firewalls.  Digital, software program, and cloud firewalls could get this NDR Necessities integration functionality sooner or later, however not in v21.5.

NDR-E
NDR Necessities is straightforward to arrange and use from the Lively Menace Response part of the product.

Different enhancements and high requested options

Entra ID (Azure AD) single sign-on for distant entry VPN

Considered one of your high requested options makes distant entry VPN simpler for finish customers, enabling them to make use of their company community credentials with the Sophos Join consumer and the firewall VPN portal:

  • Entra ID (Azure AD) single-sign on integration with Sophos Join and the VPN portal is now included in SFOS v21.5
  • It offers cloud-native integration over the {industry} commonplace OAuth 2.0 and OpenID Join protocols for a seamless expertise
  • Supported with Sophos Join consumer 2.4 (and later) on Microsoft Home windows
  • Different VPN and scalability enhancements

Person interface and value enhancements

Connection sorts have been renamed from “site-to-site” to “policy-based,” and tunnel interfaces have been renamed to “route-based” to make these extra intuitive.

  • Improved IP lease pool validation: Throughout SSLVPN, IPsec, L2TP, and PPTP distant entry VPN to eradicate potential IP conflicts
  • Strict profile enforcement: On IPsec profiles that exclude default values to make sure a profitable handshake, eliminating potential packet fragmentation and tunnels failing to determine correctly
  • Route-based VPN scalability: Route-based VPN capability is doubled with help for as much as 3,000 tunnels
  • SD-RED scalability: Sophos Firewalls now help as much as 1,000 site-to-site RED tunnels and as much as 650 SD-RED gadgets.

Sophos DNS Safety

Final yr, we launched our DNS Safety service and made it free for all Xstream Safety-licensed firewall prospects. With this launch, Sophos DNS Safety will get additional integration with Sophos Firewall.

  • New Management Middle widget to point service standing
  • New troubleshooting insights by way of logging and notifications
  • New guided tutorial on how one can arrange Sophos DNS Safety simply

Streamlined administration and quality-of-life enhancements

As with each Sophos Firewall launch, this model contains a number of quality-of-life enhancements that make day-to-day administration simpler.

  • Resizable desk columns: An extended-requested function, many firewall standing and configuration screens now help resizable column widths which might be retained in browser reminiscence for subsequent visits. Many screens resembling SD-WAN, NAT, SSL, Hosts and providers, and site-to-site VPN all profit from this new function.
  • Prolonged free textual content search: SD-WAN routes now allow looking out by route identify, ID, objects, and object values like IP addresses, domains, or different standards. Native ACL guidelines additionally now help looking out by object identify and worth, together with content-based search.
  • Default configuration: By standard demand, the default firewall guidelines and rule group beforehand created when organising a brand new firewall have been eliminated, with solely the default community rule and MTA guidelines offered throughout preliminary setup. The default firewall rule group and the default gateway probing for customized gateways are each set to “None” by default.
  • New font: The Sophos Firewall person interface now sports activities a brand new lighter, cleaner, sharper font for added readability and improved efficiency

Different enhancements

  • Digital, software program, cloud licensing: In case you missed it, all Sophos Firewall digital, software program, and cloud licenses (BYOL) now not have RAM limits. Licenses are actually strictly restricted by core rely and don’t have any RAM restrictions.
  • Bigger file dimension restrict in WAF: Helps a configurable request (add) file dimension restrict for Internet Utility Firewall (WAF), which may now scan recordsdata as much as 1 GB
  • Safe by design: We’re regularly bettering the safety of Sophos Firewall, and on this launch are including real-time telemetry gathering to flag any surprising adjustments to core OS recordsdata utilizing safe hash validation. This may allow our monitoring groups to proactively determine potential safety incidents early earlier than they’ll grow to be an actual downside.
  • DHCP prefix delegation leisure: Now helps /48 to /64 prefixes, bettering interoperability with ISPs. Router ads (RA) and the DHCPv6 server are additionally now enabled by default.
  • Path MTU discovery: This may resolve TLS decryption errors because of the newest ML-KEM (Kyber) key alternate help in browsers. The Sophos Firewall deep packet inspection engine will now routinely detect and regulate the MTU for every move, making certain optimum efficiency primarily based on particular community circumstances.
  • NAT64 (IPv6 to IPv4 site visitors): NAT64 is supported for IPv6 to IPv4 site visitors in specific proxy mode. On this mode, IPv6-only purchasers can entry IPv4 web sites. The firewall additionally helps IPv4 upstream proxy for IPv6-only purchasers.

The right way to get v21.5

As with each firewall launch, Sophos Firewall v21.5 is a free improve for Sophos Firewall prospects with Enhanced or Enhanced Plus Assist and needs to be utilized to all supported firewall gadgets as quickly as potential. This launch not solely comprises nice options and efficiency enhancements, but in addition essential safety fixes.

Sophos Firewall v21.5 is a totally supported improve from any supported Sophos Firewall firmware model.

This firmware launch will comply with our commonplace replace course of. The brand new v21.5 firmware shall be steadily rolled out to all related gadgets over the approaching weeks. A notification will seem in your native system or Sophos Central administration console when the replace is accessible, permitting you to schedule the replace at your comfort.

You may both wait till the firmware replace notification seems in Sophos Central or your native system console, or you may manually obtain the most recent Sophos Firewall firmware from Sophos Central at any time.

Right here’s a fast reminder about how one can get the most recent firmware from Sophos Central:


1. Log in to your Sophos Central account and choose “Licensing” from the drop-down menu below your account identify within the high proper of the Sophos Central console.

Licensing


2. Choose Firewall Licenses on the highest left of this display screen.


3. Develop the firewall system you’re involved in updating by clicking the “>” to point out the licenses and firmware updates out there for that system.


4. Click on the firmware launch you need to obtain (observe there’s at the moment a problem with downloads working in Safari, so please use a special browser resembling Chrome).


5. You can too click on “Different downloads” in the identical field above to entry preliminary installers and software program platform firmware updates.


Once more, the brand new v21.5 firmware shall be steadily rolled out to all related gadgets over the approaching weeks. A notification will seem in your native system or Sophos Central administration console when the replace is accessible, permitting you to schedule the replace at your comfort.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles