Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

X-Ops seems not to be working on V21 GA?

Hi,

I moved to Version 21.0 GA (Home Edition) recently.

I noticed that in control panel, no events in the log or counters are logged that X-Ops is doing anything:

A configured third party threat list (abuseipdb.com) is working properly and blocks and reports in the logs.

X-Ops (formerly ATP) was enabled the whole time, even before upgrading from 20.0 MR2  to 21.0 GA, and my Home License includes it. Signatures are also updated regularily.



Edited TAGs
[edited by: Erick Jan at 12:08 AM (GMT -7) on 24 Oct 2024]
Parents
  • SophosLabs is providing Data for x-Ops and it is more for the internal detection. So is a client infected and tries to reach an C2 Server etc.

    Third party feeds are more looking at the entire stack (Is someone, i know, simply port scanning me). 

    Using ATP / x-Ops to block Port Scanning would increase the Alert fatigue - People should react to X-Op alerts quickly and a port scanner in the internet is totally normal and happen on a daily basis. 

    __________________________________________________________________________________________________________________

Reply
  • SophosLabs is providing Data for x-Ops and it is more for the internal detection. So is a client infected and tries to reach an C2 Server etc.

    Third party feeds are more looking at the entire stack (Is someone, i know, simply port scanning me). 

    Using ATP / x-Ops to block Port Scanning would increase the Alert fatigue - People should react to X-Op alerts quickly and a port scanner in the internet is totally normal and happen on a daily basis. 

    __________________________________________________________________________________________________________________

Children
No Data