Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Diagnostics>System graphs too slow on Firewall with many network interfaces

    On our XG430 firewall we have some interfaces only the active ones are ~40 VLANs, ~40 REDs, ~30 virtual WiFi networks and adapters, ~10 physical interfaces Currently I monitor CPU load from time to time. Unfortunately, due to all graphs are preselected…
  • Any way to get the real bandwidth Sophos XG under connections ?

    Got a Sophos XG Home 19.5 as a VM under KVM and somehow it is bothering me that I do not get the real bandwidth under connections. Lets say I make a download with 4 Megabytes /s, under connections it will show me only something like 2000 KBits/ s, no…
  • Sophos XG firewall 19.5.0 Logs are not updating on GUI log viewer

    logs are not updating on GUI log viewer dis space is not high all services is also running, kindly help how to identify this issue and what action have to take to resolve -
  • Sophos XGS Firewall reports suddenly stopped working

    Hi, We are facing issues in report generation. I've checked all the logs and all things seem normal. PFB: Regards, MAS
  • Signature disk Usage reached 78%

    Hi, we are using Sophos XG-210 now signature disk usage reached 78% is there any way to clear old signature. Thanks satya
  • Logs do not specify blocked filetypes. Where do downloads blocked by filetype appear in the logs?

    I performed the eicar test where I attempt to download the Eicar virus testfile. The block page shows that the file eicar.com was blocked by filetype. However, the webfilter log shows that the website was blocked, but does not specify that it was due…
  • Syslog configuration

    Hello. We have a FW XG230 which is configuring the Syslog but you want to send the logs through a VPN site to site, the vpn connection is made and policies but it does not send any information. I would like to know where the error could be or how…
  • Firewall XGS 126

    Good morning guys. Sophos XGS Firewall 126. Is it possible to generate a report on accesses to sites by user over a period of 15 days? I can VIEW the accesses, but when I generate the report, it only generates 1 or 2 days
  • Snmp v3 Trap

    Hi guys, I'm capturing SNMP traps from an XG appliance. Everything works fine with SNMP version 2, but I'm unable to capture traps with SNMP version 3 because it seems that the XG appliance is sending an incorrect EngineID. To detect the EngineID, I'm…
  • Bandwidth Mbps Report

    Hello, I'm looking for a report that will show me the bandwidth speed over 7 days, 30 days etc. All I can find are reports that show me the total GB's downloaded. Any idea if a report showing the speed per Mbps is available? I've tried looking…
  • Add or Delete Rules and Audit Logs

    I am using Sophs XG firewall and one of rules was missing, may be someone delete or not. I am not sure. So, Where can I check the logs for add rule or delete rule logs. Thanks.
  • Question about Classification and Category and reporting?

    Hi folks about 4 months ago I asked a similar question and the answer did not clarify the issue. https://community.sophos.com/sophos-xg-firewall/f/discussions/137860/classification-question I see a number ICMP items reported in the daily reports…
  • Bug: Can I exclude domains from being logged?

    Using SFOS 19.5.1 MR-1-Build278 (SFVH (SFOS 19.5.1 MR-1-Build278)) Is it possible to exclude logging certain domains to declutter the logs. Things like outlook.com or Apple.com, or the huge number of tracking/analytics domains. I’ve tried setting…
  • how to get firewall log to wazuh dashbaord

    can any one reply me how to send the firewall xg 115 syslogs to wazuh dashboard? please!
  • Proposal for improvement on Sophos XG

    Proposal for improvement on Sophos XG logs: in the display of logs, automatically show the service and IP declared in "hosts and services" to improve readability. And improve interactions with declared objects. This means that when a port number is entered…
  • identify spikes in traffic, ssl/tls and sessions before outage

    Hey, this noon our entire network crashed for a couple of minutes. All i can see in our sophos portal is, that the "Sessions" graphs at the Control center --> "SSL/TLS" and "Network" spiked unusually high shortly before this outage happened. (see…
  • Monitoring of multiple firewalls

    Hi all, we have a lot of firewalls in a Partner Central console. I can see all the necessary alerts by selecting "Alerts" in the "My Customers" section in the left-hand menu. BUT I am searching for a way to monitor just specific alerts for specific…
  • LoggingDaemon DEAD ((SFOS 19.5.1 MR-1-Build278) )

    Good Day! I have error on my XGS4300 HA config Active-Passive. Service name Status LoggingDaemon DEAD xgs-healthmond STOPPED
  • SFOS 19.5.1 MR-1 LoggingDaemon / Garner service DEAD

    Hello, I logged into my Sophos XG firewall this morning and noticed that the LoggingDaemon/Garner service is dead. I tried restarting it from command line and of course it would not start. I started digging through related threads on this forum, but I…
  • Hi, can somebody please post Sample sophos logs ?

    Please someone can help me with sample sophos logs.
  • Sophos Firewall Log Size

    Our Sophos XG430 logs only two days backwards. That's way too small. How to increase the amount of days that will be logged?
  • Grafana Zabbix - Sophos v19.5

    Guys, has anyone had success using grafana/zabbix with Sophos in version 19.5? I found little information about sophos and zabbix, a lot of material was developed for version 18, which is no longer functional, Sophos support nobody can help. Can anyone…
  • Log file containing dhcp client requests?

    I'm trying to locate the logfile that would track the firewall's own client dhcp request over a WAN connection when trying to get an ip from a Cradlepoint modem? My XG210 (SFOS 19.5.1 MR-1-Build278) is having trouble, but when I connect my laptop to the…
  • XGS logfiles unavailable with WinSCP?

    I have used WinSCP with my XG firewall to read the logfiles because I'm not a linux propeller-head guru. Now I'm having an odd WAN dhcp problem on my new XGS firewall, when I go to the logs up pops a dialog box saying /logs/tslog is empty. What's up with…
  • DNS logging of resolutions against XG dns configuration

    With using the XG as DNS responder, is there a logfile that is recording the requests? By looking at Log file details - Sophos Firewall none of those files contain the actual logging of the requests and respondses.