Sophos UTM: Up2Date 9.700 Released

Sophos has, after a very short EAP (Beta), released 9.7 as GA, this is what it contains and here it how to download it – it will be rolled out in phases:

  • In phase 1 you can download the update package from the download area.
  • In phase 2 we will make it available via our Up2Date servers in several stages.
  • In phase 3 we will make it available via our Up2Date servers to all remaining installations.

What’s new in UTM 9.7?

  • Support for new APX Access Points
    In addition to the legacy AP series access points, UTM 9.7 brings support for the newer Wave 2 APX series access points which can now also be added and managed with UTM 9. This includes support for APX 120, APX 320, APX 530 and APX 740.
  • Certificate Chain support for WebAdmin and UserPortal
    Full certificate chains that are uploaded to UTM for use with WebAdmin and/or UserPortal will no longer be split but will be delivered in full when accessing WebAdmin and/or UserPortal and web browsers will no longer display warnings for these certificates.
  • Certificate Chain Support for WebProxy
    When using an intermediate certificate to sign HTTPS decryption certificates in WebProxy, WebProxy will now build and return a full certificate chain for the generated certificate to avoid browsers showing a warning when not explicitly trusting the intermediate certificate. The root certificate has to be available within the verification CAs.
  • New RED Site 2 Site Protocol
    RED Site 2 Site connections in UTM will now use the same protocol used within XG Firewall for RED Site 2 Site connections. This removes the need to specify legacy RED site 2 site connections in XG Firewall and provides enhancements to the RED site 2 site implementation in UTM.
  • Retirement of UTM Endpoint Management
    As announced with UTM 9.6, UTM endpoint management will be end of life by the end of this year. UTM 9.7 will no longer include the option for Endpoint Management for the UTM Managed Endpoints, Sophos SEC integration is still part of UTM 9.7.

 

Up2Date Information

9.7 EAP1 to 9.7 GA

News

  • Features Release
  • .
  • Support for new APX AccessPoints
  • Certificate Chain support for WebAdmin and UserPortal
  • Certificate Chain Support for WebProxy
  • New RED Site 2 Site Protocol
  • Retirement of UTM Endpoint Management

Remarks

  • System will be rebooted
  • Configuration will be upgraded

Bugfixes

  • NUTM-10485 [Email] POP3 E-Mail blocked message won’t be displayed properly in some MS Outlook versions
  • NUTM-11141 [Sandstorm] Add support for Sandstorm’s Frankfurt data centre
  • NUTM-11162 [WAF] Authentication through WAF with URL hardening enabled and umlaut in password fails
  • NUTM-11202 [Web] Conform to Apple’s new certificate requirements introduced in iOS13 and macOS10.15

9.6 MR5 to 9.7 GA

News

  • Features Release
  • .
  • Support for new APX AccessPoints
  • Certificate Chain support for WebAdmin and UserPortal
  • Certificate Chain Support for WebProxy
  • New RED Site 2 Site Protocol
  • Retirement of UTM Endpoint Management

Remarks

  • System will be rebooted
  • Configuration will be upgraded
  • Connected REDs will perform firmware upgrade
  • Connected Wifi APs will perform firmware upgrade

Bugfixes

  • NUTM-10804 [Access & Identity] strongSwan vulnerability fix (CVE-2010-2628, CVE-2018-17540)
  • NUTM-10485 [Email] POP3 E-Mail blocked message won’t be displayed properly in some MS Outlook versions
  • NUTM-10745 [Email] Quarantine mail older than 14 days are not getting removed
  • NUTM-10958 [Email] Quarantined SPX Mails which are released are still available on UTM
  • NUTM-10192 [RED] Patch OpenSSL (CVE-2018-0732)
  • NUTM-11141 [Sandstorm] Add support for Sandstorm’s Frankfurt data centre
  • NUTM-10454 [WAF] SAVI integration doesn’t support scanning files larger than 2GB
  • NUTM-10873 [WAF] Underscore in DNS-Hostname makes WAF unusable
  • NUTM-11162 [WAF] Authentication through WAF with URL hardening enabled and umlaut in password fails
  • NUTM-11202 [Web] Conform to Apple’s new certificate requirements introduced in iOS13 and macOS10.15

Download

While the release is in soft-release phase, you can find the Up2Date package at:

If you are already running 9.7 EAP1, please use the following package:

15 Comments

  1. Thorsten Sult

    I already installed it yesterday. No problems so far. Also the RED15 works. I hope that it stays that way.

    Reply
    1. Martin (Post author)

      YUP, ran with it since EAP1, but omg, we have had many broken REDs at work after 9.602-605 🙁 24 pieces send for RMA….customers angry…

      Reply
  2. Thorsten Sult

    I’ll try a RED 50 today. See what happens. Greetings!

    Reply
    1. Martin (Post author)
  3. Thorsten Sult
    1. Thorsten Sult

      This problem is fixed with 9.700-5.

      Reply
      1. Martin (Post author)

        looking forward to 9.700-4 -> 9.700-5 update 😀

        Reply
  4. Thorsten Sult

    You can use the same Updatefile: download.astaro.com/…/u2d-sys-9.605001-700005.tgz.gpg

    Reply
    1. Martin (Post author)

      Ah! – That was a new one 🙂
      Thanks for sharing Thorsten 😀

      Reply
    2. Martin (Post author)
    3. Thorsten Sult

      My bad. This does not work with the same update file. The UTM indicates that it could install from 9.700-4 to -5. But after a restart it stays on -4. Sorry for the misinformation.

      Reply
  5. Youf

    i update mine to 9.700-5 but i can not send and receive email

    Reply
    1. Martin (Post author)

      Hmm..have not have any issues with that ?!

      Reply
  6. Shahin

    Any idea when update 9.605001-700005 will be available for auto update? MY SG310 is at 9.605001

    I am a bit confused here, at the FTP site see:

    9.605001-700005 and last update is 9.700004-700005

    Reply
    1. Martin (Post author)

      They are still doing staged rollouts, it will come eventually, they just rolled out some more yesterday, but you can fine us this to get there now, I did:
      ftp://ftp.astaro.de/UTM/v9/up2date/u2d-sys-9.605001-700005.tgz.gpg

      Reply

Leave a Reply to Thorsten Sult Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close