VPN Disconnect Alerts

Is there a way to disable the alerting of L2TP / IPSec client disconnects. Each disconnect generates an alert to Sophos Central. This is unnecessary, generates undo noise and is totally annoying.  Site to Site VPN alerts are acceptable and desired, but not client to FW VPN disconnects.

LThibx



Updated Tags
[edited by: Gladys at 3:05 PM (GMT -7) on 22 Aug 2023]
Parents
  • Hello Lonnie,

    Good day and thanks for reaching out to Sophos Community, 

    Are these Email Alerts? If it is you may disable this by creating a custom email alert on Sophos Central under Global Settings > Configure email alerts > Custom Rule > Then create "Set by Category" and uncheck the Category "Connectivity" Proudct Affected: "Firewall"

    Otherwise, if these are from Alerts tab, And iff you want to just stop the alerts or add some control for these, This should be a feature request you may get in touch with you local Sales Engineer/Account Manager or you you can use the in-product feedback feature on the top right corner of your Central Dashboard > Help > Give Feedback 

    Many thanks for your time and patience and thank you for choosing Sophos.

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Raphael,

    They are both Email Alerts & also from the Alerts tab in Sophos Partnern(SP) & Central Admin (CA).

    Are these Email Alerts? If it is you may disable this by creating a custom email alert on Sophos Central under Global Settings > Configure email alerts > Custom Rule > Then create "Set by Category" and uncheck the Category "Connectivity" Proudct Affected: "Firewall"

    This can't be done in CA as they are managed in SP...but anyhow, In SP...Settings & Policies...Configure Email Alerts...Set by Category, I do see the Connectiviity...Firewall check box. But does this control all connectivity alerts for the FW? I DO still want to see alerts for FW & Site to Site VPN disconnects or other FW connectivity alerts. I just don't want to see Client VPN disconnects.

    At each XG Firewall, there are notification settings: System Services...Notification list...VPN, there are settings for email notifications for controlling some types of VPN messages. In my case, most are L2TP / IPSec connections and there is nothing there for that type:

    I believe I had put in a feature request as I have been experiencing this ever since I started with Sophos FWs...probably about 4 / 5 years ago. Sophos doesn't seem to think that being annoyed every day, multiple times a day is important enough to add it.

    Thought that by now with all the changes to SP & CA, that maybe in was incorporated there.
    I will use the Feedback link you suggested.

    Thanks
    Lonnie

Reply
  • Hi Raphael,

    They are both Email Alerts & also from the Alerts tab in Sophos Partnern(SP) & Central Admin (CA).

    Are these Email Alerts? If it is you may disable this by creating a custom email alert on Sophos Central under Global Settings > Configure email alerts > Custom Rule > Then create "Set by Category" and uncheck the Category "Connectivity" Proudct Affected: "Firewall"

    This can't be done in CA as they are managed in SP...but anyhow, In SP...Settings & Policies...Configure Email Alerts...Set by Category, I do see the Connectiviity...Firewall check box. But does this control all connectivity alerts for the FW? I DO still want to see alerts for FW & Site to Site VPN disconnects or other FW connectivity alerts. I just don't want to see Client VPN disconnects.

    At each XG Firewall, there are notification settings: System Services...Notification list...VPN, there are settings for email notifications for controlling some types of VPN messages. In my case, most are L2TP / IPSec connections and there is nothing there for that type:

    I believe I had put in a feature request as I have been experiencing this ever since I started with Sophos FWs...probably about 4 / 5 years ago. Sophos doesn't seem to think that being annoyed every day, multiple times a day is important enough to add it.

    Thought that by now with all the changes to SP & CA, that maybe in was incorporated there.
    I will use the Feedback link you suggested.

    Thanks
    Lonnie

Children
No Data