Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • The firewall web admin is not accessible from the LAN.

    Verified that the firewall is accessible via ping on the LAN. Successfully obtained SSH access to the firewall. Enabled appliance access, but the firewall was still inaccessible. Determined that the apache and reportdb services are dead on the firewall…
  • XG 115

    I have an XG 115 from 2019 that is most likely up to date on firmware upgrades. I do not have a console cable, and I have a Mac with Ventura OX, and cannot find a way to install PuTTy. How do I reset the firewall back to factory settings or change the…
  • Bridge mode

    Hi, I have a Sophos 2100 with port 1 and 2 that are in bridge mode without IP where one is WAN and the other DMZ with public IP's. The problem is that I can only access these IP's outside Sophos but I needed to access them from my LAN network to manage…
  • Web console access via WAN 19.5.3

    First off I understand the security implications of enabling web admin access via WAN. I've added a Local services ACL exception rule to permit one IP to the WAN interface for SSH/HTTPS access, however I still cannot enable https on the WAN interface…
  • gui port

    i can't Access My firewall GUI what type in device console to get port to access my firewall from web Plz help me
  • unable to access sophos firewall gui

    Hi, I am unable to access my firewall gui even after putting my ip address and port:4444 need assistance
  • FW vm login page Delay

    Hi Team, I recently install FW on VMware but issue is the login web page is taking too long to load. Using ssh I can easily and quickly go to the device setting but managementip:4444 is taking too long(20-30mins) to load. I used all the browser but…
  • Help! Firewall is "reachable" from Internet, but not able to connect to VPN or internal servers

    I am currently off site with no physical access to my firewall. Firewall is reachable from outside, e.g. WAF port 443 gives answer to telnet, and in browser any configured site is reported as "503 Service unavailable". Also SSL.-VPN port is listening…
  • Sophos XGS - Device Access profile for MFA admin only

    I am running Sophos XGS 19.5.2 MR-2-Build624 in an active / passive cluster. I have configured IPSec VPN for 150+ remote users. I have enabled MFA for all Users. I have a small 3rd line support team, but want to provide access to my servicedesk to administer…
  • Admin Accounts - Why can't I give an account access to SSH into the firewall

    We have multiple techs in our organization and I don't share the default ADMIN account with them. I have set them up with their own accounts. However, if they are ever troubleshooting the firewall with a SOPHOS Engineer, almost immediately the engineer…
  • Restricting Access to Admin Web Interface

    Hi I am using XG-115 firewall in my network. We got number of VLANs Can someone help me in restricting access to the Web Interface (and Putty) of the Sophos Firewall from certain VLANs. For example, let's say I got VLAN1, VLAN2, VLAN3 and VLAN4…
  • Site can't be reached

    Hi everyone. I have downloaded the sophos firewall home edition. I have setup with VMware workstation and done the configuration on https:10.1.1.200:4444. The configuration went well and I finished the installation then the firewall rebooted. Now…
  • access denied to the webconsole

    after validation of the capchat, access denied to the webconsole. The certificate is valid, the acls are well saved to allow access to the webconsol. What is going on ?
  • Device Access

    Hello, I can't find any information about how the services in Local service ACL work. Is there a page that explains what all the Local service ACL services do? A table with every single service explained would be great.
  • Unwanted Parenting - Why does SOPHOS insist on removing features "for our own good"?

    SOPHOS markets their XGS product to network administrators, who are professionals in their field. These are expensive devices that owned by the customer, and should be up to the customer how they wish to deploy\configure\use them. SOPHOS, however, is…
  • Gui can't be reached

    Hi everyone So I have downloaded the sophos firewall did the setup in vmware. I did do the initial wizard setup. Then I got logged into my sophos firewall gui login page. I was busy setting up but I forgot to plug in my laptop so everything shutdown…
  • Webadmin logon - slow loading of captcha java script

    When managing firewalls at remote sites that have a small or overloaded WAN line, I notice, it takes a long time, until the captcha fully loads. The ammount of time depends on the WAN situation on the remote side and can take up to 30 seconds. it looks…
  • network outage with full /tmp dir on firewall, Webadmin inaccessible, no alert

    Hi, the primary node of our firewall last night decided to go out of service, the last thing we could see was a full /tmp partition: At 2023-07-05 08:55 when logged in SSH to C420xxx9CF, it showed /tmp full: GMTLOG: could not write temporary statistics…
  • Error using the Wabadmin interface

    When using the webadmin portal of our Sophos XG, I had massive problems with the operation today. The problems had expressed themselves in the sense that there were either messages during use that the page could not be loaded or that the loading circle…
  • Firewall web page login failed

    Web password not accept unble to access firewall.
  • Additional SSH users

    In many environments there is a strict requirement that each administrator has their own administrative user. However, since many logs can only be viewed via the console, every administrator has to know the access data for the admin user. Will it be possible…
  • I cannot access WEB Admin or SOPHOS XG Portal

    Kindly help, I can not access my xg firewall but the ip is responding to ping
  • How to ACL differ from Firewall rules

    Im using the Sohpos UTM Virtual Applicance MR2 Version .. I have noticed that despite creating a drop rule for all zones, networks and services, the ACL still stands in control and firewall rules take no effect, only if the LAN Access at ACL device access…
  • invalid logins - public IP blocked for 5 minutes - can login VPN anyway. why?

    Hello, today we had a strange situation on SFOS 19.5.1: a VPN user logged in with wrong credentials several times. In the XG log this was shown as VPN auth failure in log as expected. SFOS does not log the client IP for failed logins anymore,…
  • RMA replacement for HA pair

    Hi, I have just received an RMA replacement for a secondary unit that died and was part of a HA pair. What are the steps that I need to replace this unit. I am struggling to log on to it with admin/admin, is this the wrong logon? I can see that…