Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Alert/Notification when a firewall rule/nat rule is used

    Hi, I would like to know whether the above is possible. Basically, the rules in question are logged at the moment, and I see them appearing in my logs. But I'm trying to find out whether I could get a notification (ideally, on my phone ?) that the…
  • Persistent iptables commands

    Hi everyone, to make a particular ipsec work correctly, I have to manually set the mtu through advanced shell: iptables -t mangle -I POSTROUTING -d 192.168.15.0/24 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1300 This way everything works smoothly…
  • Policy Tester Firewall Rules

    hi, we have configured simple firewall rules and would like to test them with the Policy Tester. Unfortunately the traffic is detected as Blocked and the traffic is not assigned to any firewall rule. An Any to Any rule did not help either. What is the…
  • Dropping traffic from external ip address

    I am struggling to get a working firewall rule to drop or reject traffic from an external ip address. My mail server keeps getting hammered by IP addresses it reports as being from Iran. I created a firewall rule at the top position but it isn't having…
  • Can't access network and internet

    We have 5 firewall in different location and each firewall have different local IP address. Unit 1 has 192.168.1.1 and Unit 2 has 192.168.2.1 and Unit 3 has 192.168.3.1 and so on. And if I take a laptop from Unit 1, which has IP range 192.168…
  • SOPHOS XG 19 Streaming issue (HBOMAX)

    Sophos XG 19 GA intel xeon D, 4x10gbe 16GB, 1TB SSD, DPI ssl / tls APPLE TV I am having a lot of issue with streaming services since updating to XG19 getting constant buffering from streaming services Major Issue with HBOMAX error can't connect…
  • SOPHOS XG230 wont connect to the internet after update

    Hi i have a firewall that updated from 18.0 to 19.0 the we startedfacing network challenges some users are connecting, some cant connect. If we roll back users can connect but now if we roll back users cant connect to the internet
  • SOPHOS XG Firewall

    Hi, Is there anyway i could export the firewall rule to CSV file. Im using xgs4300 firmware version SFOS 18.5.1 MR-1-1-Build365 Thanks and best regards, Nidzpar
  • IPS Service - with no FW rules - Prevents Certain Sites from Loading

    I'm running V19 in bridge mode. Very basic setup, haven't really gotten far with it yet. I've noticed that even though I have no firewall rules with IPS enabled, certain sites - like this one(!) time out unless I stop the IPS system service under "system…
  • Simple firewall rules doesn't trigger

    I've recently updated to latest version (19), not sure if it's related. I've added a simple rule to allow ssh between two machines in different vlans, but didn't work. I tried stripping down some restriction to Any-Any between the whole subnets and…
  • help

    how can we control in sequence rule in sophos?
  • Firewall Rules Don't Apply to VLAN Interface

    I have a guest WiFi network running on VLAN40. I'm trying to create firewall rules for this network but when I select the VLAN interface (#Port8.40) in Source networks and devices, it has no effect at all. I can define the network subnet here instead…
  • No access to DMZ Gateway

    Hi Guys, I am facing something strange, I can not reach my DMZ GW from a LAN but I can reach the devices in the DMZ. Is this something someone has encountered? Is it by design that the GW isn't reachable? XG125 v19. Thanks for the help.
  • MySQL Replication Broken by 18.5.2 and 18.5.3

    I have a pair of RHEL 8.5 servers - one on a cloud host and one on a server in my office behind a Sophos XG106w. Both servers running MySQL 8.0.28 as a master/slave pair - the cloud one is the master and the local one a slave for backup purposes. All…
  • After changing the interface, the rule setting must be turned off and then turned on for normal operation

    The equipment that connects to the top or bottom of the firewall has changed. At this time, the snat or dnat policy set on the device is not applied. You have to turn off the policy and then turn it on for it to work properly. XG430 (SFOS 17.0…
  • Simple Rule Not Working

    I'm trying to create a very simple firewall rule to apply traffic shaping on a specific source IP but when the rule is enabled all attempts to access the Internet from the source IP device times out. I have other similar rules that are working fine but…
  • No WAN-Access from DMZ

    Hi all, for more than a week I'm trying to configure WAN-Access for a franking machine connected to the DMZ-Port and it's driving me nuts. The unit doesn't get access to the Internet and its franking service provider. Here is the setup: XG135…
  • Drop Outbound Connections by destination country

    Using the rule below i see unexpected behavior in the logs. The log excerpt shows three allowed connections. Each of these connections is to a country that is blocked. They do not show a destination port. and they appear to always be destination port…
  • Drop Inbound SMTP connections from Specified countries

    Using the rule below i see unexpected behavior in the logs. The log excerpt shows three connections. Each of these connections is from a country that is blocked. The rule seems to block all other protocols from blocked countries except SMTP. It allows…
  • Close connections TCP Activity

    Dear, good morning. My question is the following. There are moments when I get connections from computers that consume a lot of download bandwidth. And this makes my network slow. Although I have policies for traffic, I would like to know if there is…
  • Specific network cannot ping

    Hi, I create a network 172.19.4.0/24 for WIFI. Is connected on my port 5 DHCP is running Giving IP from 172.19.4.10 to 172.19.4.200 GATEWAY: 172.19.4.1 (PORT 5 IP) Everything work well but somedays : you are connected to the network…
  • dropouts lan to wan with wan-zone and multiple IPs/nat rules

    Hi there, I am facing an issue and I am not quite sure where to go from here. The issues are on Wifi and on cabled workstations. It looks like a lot of people are having connection issue especially when doing team-calls or whatsapp. What I see on…
  • Issue with schedule on a rule

    Hi, I have a rule defined to be accept only during a schedule: All users from a specific clienteles group can have access to internet only during a scheduled period from 8:30 am until 11:00 pm On daily basis, it doesn't work at 9:30 am, I have to…
  • How to allow IP list to access internet

    Hi, would appreciate some help. I assign IP addresses to all devices at home. I would like to allow a list of IP hosts on LAN to be able to access the internet WAN at any time. I want to be able to easily add or delete IP addresses from this list. So…
  • How to prevent Android Users from Accessing internet

    Hello, * Company employees access internet through captive portal using their cell phones, how I can prevent them from accessing the internet with their android phones during the work hours, and I know I can prevent them by blocking the mac address…