Site icon Sophos News

Sophos Firewall v21.5 is now available

sophos-firewall

Following a very busy and successful early access program, the Sophos Firewall team is pleased to announce that v21.5 is now available to all licensed Sophos partners and customers.

This release brings an industry-first innovation: integrating Network Detection and Response (NDR), which enhances active threat detection on your network.

What’s new overview

Watch this brief video for an overview of the release highlights:

Learn more

Watch these demo videos for deeper insights into how to make the most of the major new features or consult the previous series of articles on this release:

Additionally, review the What’s New Guide, consult the Release Notes, or read on for more details.

Full details

An industry first innovation: NDR Essentials

Sophos is the first to integrate an NDR solution with a firewall, further extending Sophos Firewall’s advantages with XDR and MDR use cases.

We’ve taken the novel approach of implementing NDR in the Sophos Cloud to offload all analysis processing from the firewall, eliminating any performance hit.

We’re calling this NDR Essentials, and the best part is, we’re enabling this for all XGS Series firewall customers who have the Xstream Protection license bundle – at no extra charge.

How NDR Essentials works

Sophos Firewall’s XGS Series captures meta data from TLS encrypted traffic and DNS queries and sends that information to NDR Essentials in the Sophos Cloud where the data is analyzed using multiple AI engines.

It can detect malicious encrypted payloads without performing TLS decryption. This addresses a huge blind spot in most organizations where man-in-the-middle TLS inspection is not being used for performance, usability, or security reasons.

In addition, the NDR Essentials domain generation algorithm detects new and suspect domains generated by malware that are often a key indicator of compromise. In fact, in many cases, NDR Essentials can detect new C2 domains before they are even registered.

The meta data extraction is performed by a new lightweight engine implemented on the Xstream FastPath, and as a result, one caveat with this new capability is that it is only available on XGS Series hardware firewalls.  Virtual, software, and cloud firewalls may get this NDR Essentials integration capability in the future, but not in v21.5.

NDR Essentials is easy to set up and use from the Active Threat Response section of the product.

Other enhancements and top requested features

Entra ID (Azure AD) single sign-on for remote access VPN

One of your top requested features makes remote access VPN easier for end users, enabling them to use their corporate network credentials with the Sophos Connect client and the firewall VPN portal:

User interface and usability enhancements

Connection types have been renamed from “site-to-site” to “policy-based,” and tunnel interfaces have been renamed to “route-based” to make these more intuitive.

Sophos DNS Protection

Last year, we launched our DNS Protection service and made it free for all Xstream Protection-licensed firewall customers. With this release, Sophos DNS Protection gets further integration with Sophos Firewall.

Streamlined management and quality-of-life enhancements

As with every Sophos Firewall release, this version includes several quality-of-life enhancements that make day-to-day management easier.

Other enhancements

How to get v21.5

As with every firewall release, Sophos Firewall v21.5 is a free upgrade for Sophos Firewall customers with Enhanced or Enhanced Plus Support and should be applied to all supported firewall devices as soon as possible. This release not only contains great features and performance enhancements, but also important security fixes.

Sophos Firewall v21.5 is a fully supported upgrade from any supported Sophos Firewall firmware version.

This firmware release will follow our standard update process. The new v21.5 firmware will be gradually rolled out to all connected devices over the coming weeks. A notification will appear on your local device or Sophos Central management console when the update is available, allowing you to schedule the update at your convenience.

You can either wait until the firmware update notification appears in Sophos Central or your local device console, or you can manually download the latest Sophos Firewall firmware from Sophos Central at any time.

Here’s a quick reminder about how to get the latest firmware from Sophos Central:


1. Log in to your Sophos Central account and select “Licensing” from the drop-down menu under your account name in the top right of the Sophos Central console.


2. Select Firewall Licenses on the top left of this screen.


3. Expand the firewall device you’re interested in updating by clicking the “>” to show the licenses and firmware updates available for that device.


4. Click the firmware release you want to download (note there is currently an issue with downloads working in Safari, so please use a different browser such as Chrome).


5. You can also click “Other downloads” in the same box above to access initial installers and software platform firmware updates.


Again, the new v21.5 firmware will be gradually rolled out to all connected devices over the coming weeks. A notification will appear on your local device or Sophos Central management console when the update is available, allowing you to schedule the update at your convenience.

Exit mobile version