This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint causing 1000s of Audit Failures in Event Viewer

I've seen some reports, so I decided to take a look myself.

I noticed having lots of Audit Failures in Event Viewer. Some troubleshooting later, I found out following is happening:

Default state of the Audit Policy "Filtering Platform Packet Drop" is No Auditing. After installation of Sophos Server Protection (Core Agent, A/V, Intercept X), I saw it change to "Failure", and logs starts to appear. Setting back to No Auditing, solves the "problem".

While I do get what this Policy does, I wonder why Sophos is changing the auditing of default windows firewall?


This thread was automatically locked due to age.