Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Odd issue with internet access

    Hi, I did several research and looked everywhere in the firewall, but I was not able to find an answer to my problem. Basically: - I have an XGS126w with the latest OS - The setup is fairly simple: 1 LAN on a private /24 subnet --> The Firewall…
  • DHCP Release issue

    Hi All, I am hoping someone can help me. We've just implemented Sophos XG. Randomly we are having devices not being able to get an IP address from the Sophos DHCP I setup. They get a 169.254.x.x address. The weird thing is sometimes if we leave it…
  • Firewall role configuration

    Hello, I have one question, please. We want to renew our TI SAX security certificate, and the Tisax forwards us a VM scan appliance to run in our network to discover if we have any security issues. Besides this VM appliance, he asks us to give this machine…
  • Lost access/ internet after creating a bridge

    I'm using port 1 as LAN, port 2 as WAN, and port 3 as backup WAN. So far, so good. I decided to try creating a bridge, since, why not? I have excess ports. I chose ports 5 and 6, assigned both to LAN, and gave it an IP address of 192.168.1.x. My firewall…
  • 2CORE -SINGLE FIREWALL--UPLINK-CONNECTIVITY

    Hi, we have two core switch with single sophos-xgs firewall.only internet traffic coming to firewall all Lan gateway are configure in core-switch.both core are connected with VLT. query ----how to connect two uplink with firewall and what need to…
  • Configurazione di Split DNS

    good morning we should create a configuration for our 3cx switchboard that resolves the name of the 3cx FQDN to an internal address of our network. The device supplied is XG106w (SFOS 19.5.3 MR-3-Build652), I have not found any guides that solve the problem…
  • Slow SharePoint Downloads

    I'm at a loss here. Downloads from SharePoint seem to be capped at around 500kbps. Downloads from other websites are fine and come down at several Mbps. Another site a few miles away with the same XGS 3300 model firewall and basic config, same ISP, gets…
  • Change Subnet to /22

    Im using Sophos XG230 and Ive change the subnet to /22 (192.168.0.1 - 192.168.3.254 from /24 (192.168.0.1-254). now I test to reserve IP 192.168.2.1 and put that IP to laptop, the problem is I cannot ping the Firewall(192.168.0.1) so the laptop cant access…
  • Sophos Firewall: v20.0 - PXE-Boot Problems

    Hello everyone. I would like to share my experience regarding PXE boot with you. I have already solved the problem with thePXE boot on our old XG2300 v19.5 with the help of the forum and Sophos support. Entered the required options in the DHCP server…
  • WWAN ATT

    I have a simcard in WWAN unit but ATT does not seem to know any info on setting it up. Does anyone know what all I need to put in? Thanks.
  • Need control bandwidth cloud website.

    Hi, My business use google workspace for all service ( Gmail, Google Drive, Sheet, Doc, Slide, Etc.), We need control bandwidth for usage internet. We try config traffic shaping under application setting, i think this way only application. But if…
  • More details on how to do WAN Link Aggregation?

    I am using this documentation to understand how to do Link Aggregation, but I have a couple of questions to fill in the gaps in the documentation: https://doc.sophos.com/nsg/sophos-firewall/19.5/help/en-us/webhelp/onlinehelp/AdministratorHelp/Network…
  • XG210 VLAN proxy bypass

    We are setting up a new VLAN for handheld scanners, We require for staging and Sophos Mobile Management that the handheld scanners also have a connection to a FQDN Group of Google and Sophos websites. When I set this up I see the scanner trying to connect…
  • DISABLE BACK UP WAN | DYNAMIC IP

    Hello, We have two ISPs set up for our client's firewall. The main one is static, and the other backup is dynamic. My concern is that if the failover ISP is on dynamic, that could prevent us from remotely getting into the firewall to switch the failover…
  • Simple network design question

    Hi, I have an XGS firewall with 10gbe module and two L2 switches with spf+, one of which is poe. What would be the best way to maximize performance and pass all vlans on all switches because they still don't support stacking? Should I create a LAG…
  • XGS 107w 4G WAN Fallback not working

    Hi, I've setup 4G WAN fallback if the primary NBN connection goes down. I've confirmed the 4G WAN connection is working. However, when the primary WAN connection goes down, it's not falling over to the 4G WAN. This is the failover rule I have in…
  • Can the DHCP server register a name/address in DNS

    Can the DHCP server register a name/address in DNS
  • DHCP Static IP mapping for same client multiple networks?

    The problem from the discussion: https://community.sophos.com/sophos-xg-firewall/f/discussions/74013/dhcp-static-ip-mapping-for-same-client-multiple-networks affects me too . the feature request https://ideas.sophos.com/forums/330219-xg-firewall…
  • XGS2100 bridge to connect switches

    We have set a bridge on ports 3 and 4 to plug the Aruba 2930 switches in parralell vs daisy chain, the bridge works as expected except we had an issue with printers. the pritners connected to port 3 work, but the printers on port 4 stop connecting, has…
  • Regarding Internet Speed Assessment and Automation with Sophos Firewall

    Hello Everyone, I hope this message finds you well. I would like to understand if there is a method available to assess the internet speed of various ISPs configured on separate WAN ports within the Sophos Firewall. Additionally, It is possible to…
  • DNS Management/Implementation

    I have the below deployment on my environment Devices/Servers - Sophos XG 210 FW (Assigned it's own Public IP [i.e. x.x.x.67]) - Switch (Cisco ) - Connects all the APs and Servers - 3 Server (1 Web server with it's own Public IP [i.e. x.x.x.68…
  • XGS - internal DNS issue

    Good day, I am facing a strange issue with domain name resolution. Some domains are not resolved by XGS internal DNS. Below are nslookups from XGS Advanced shell. It used to work but suddenly stoped few days ago. Thank you for advice. DNS Configuration…
  • Update DDNS with current active gateway public IP

    I have two ISP's connected to my firewall, one is the dedicated WAN connection & the second is the failover WAN Connection. both have static IP's. I need an option to have the firewall update a single DDNS Address when the Dedicated WAN Connection fails…
  • split Vlan on same ports to another port

    In my early days we put the default + vlans on all port 1 (1 gigabit), since we having some issue with smb traffic and sometimes freezes/spikes, i wanted to try to change that. So i thought i could use port 4-8 and trunk them together and allow those…
  • traffic shaping slows internet speed

    Hi all i have a 76 Mb bandwidth , 60 PCs and i made 12 rules for each department in my workplace and allowed users in each rule to access internet by their MAC address and i made traffic shaping for each rule 4-6 Mb guranteed and then tested each rule…