I've seen some reports, so I decided to take a look myself.
I noticed having lots of Audit Failures in Event Viewer. Some troubleshooting later, I found out following is happening:
Default state of the Audit Policy "Filtering Platform Packet Drop" is No Auditing. After installation of Sophos Server Protection (Core Agent, A/V, Intercept X), I saw it change to "Failure", and logs starts to appear. Setting back to No Auditing, solves the "problem".
While I do get what this Policy does, I wonder why Sophos is changing the auditing of default windows firewall?
Thanks
This thread was automatically locked due to age.