Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • traffic shaping slows internet speed

    Hi all i have a 76 Mb bandwidth , 60 PCs and i made 12 rules for each department in my workplace and allowed users in each rule to access internet by their MAC address and i made traffic shaping for each rule 4-6 Mb guranteed and then tested each rule…
  • Voice Issue

    Hi Guys, Need urgent help. Actually I have configured SSL VPN on Sophos XG Firewall for voice communication work from home. My softphone connects fine but when I dial a test call it gives the error "VOIP connection can not be established". I don…
  • IP Reservation in the DHCP pool

    Hello, I found a few threads, that there was no traditional DHCP reservation and you have to use a static MAC Mapping outside the DHCP pool. Did that feature got implemented yet or do you still need to use that way? If not, then is there a nown…
  • How to ping from CLI on Sophos XG 19

    I'm trying to send a ping to an external address using a specific interface; the documentation is not clear to me and every attempt tried throws me a "% Error: Unknown Parameter" ping -a <sourceip> <destinationip> % Error: Unknown Parameter
  • How to tell if there is a FlexModule installed on an XG or XGS VIA GUI or CLI

    Hi, Is there anyway to tell if a Flexi Module is installed besides looking at it physically ?
  • Changing DHCP DNS for LAN Clients to Internal Windows DNS

    Hi, XGS2300 is our DHCP Server. Currently, DNS settings under Network > DHCP > Default_DHCP_Server are the gateway itself for the Primary, and our ISP for the secondary DNS Servers. Works fine. Our external DNS servers (Network > DNS) are our ISP…
  • Is VRRP finally available on XGS Firewall?

    Simple Question. I know about 6 years ago this was a suggested feature and it is currently being used for HA configuration of XG Firewalls, but I do not see it available for use/configuration outside of that. When will this be added? Is it anywhere…
  • dhcp option 43 for unifi

    hi, Can anyone tell me what the format is to get the dhcp option to work for unifi please on a sophos XG? I am using option 43 and have tried the ip of the unifi controller. This worked fine on v19.5.2 but since updating to v19.5.3 it now doesnt work…
  • Multiple VLAN on each port

    On XGS series firewall, how to assign multiple VLANs on each port (port 1-8), such that each port has a native VLAN, and some allowed VLANs. e.g.: port 1, native VLAN 1, allowed VLAN 2,3,4 port 2, native VLAN 2, allowed VLAN 4,5,6 port 3, native…
  • SET DNS Preference for each gateway

    We have multiple ISP gateways per XG. Is there a way to set DNS server preferences for each particular gateway? WHY? I've added NextDNS as an additional layer of security and for analytics to function properly for each profile I need DNS servers…
  • Can I define both vlan and per-user bandwidth in Sophos Firewall?

    Hi , Can I define both vlan and per-user bandwidth in Sophos Firewall? For example , when setting a limit to traffic shaping vlan on Fortigate ; per-ip shaping could also be done.
  • Combining LAN Ports / VLANS / DHCP

    Hi everyone, I was wondering if anyone can help. I have the follow: An XGS2100 I need to connect 4 separate switches into it. I need the 2100 to: 1. Act as a gateway for 5 different VLANS across the 4 ports irrespective of when the gateway…
  • MIB OIDs not supported for Zabbix - XG FIREWALL SOPHOS

    I've tried using the two templates available in the zabbix repository, but without success. Both models do not support OIDs. I manage to communicate my firewall with Zabbix by SNMP, but it is not possible to communicate data because we don't have a template…
  • Unable to obtain IP address from DHCP created for VLAN interface.

    Hi! Unable to obtain IP address from DHCP created for VLAN interface. The L2 switch is a NETGEAR GS308T and is trunked to the Sophos XG Firewall. I have an access point connected to the GS308T and cannot get an IP address via DHCP on my iPhone or…
  • My vlan's get can't an ip address or internet access via DHCP relay (windows server 2022)

    Hello, This is my L2 schéma and L3. I have 2 xg 115 firewall, a sophos switch. I also have a windows server 2022 how have a DHCP server. I want my pc's to get an internet access and to get their ip form my windows server 2022. I first tried…
  • Configuring 31-bit subnet in DHCP on a 31-bit subnet interface

    I am using Sophos Firewall Home on a Protectli Vault FW4B. 5 VLANS are defined in Sophos and I am using CISCO SG-200 switch. I have dedicated one VLAN specifically for an IP camera in my home. Everything is working great but I want to configure that…
  • Client DHCP renewal is blocked by XG106 firewall

    We have experienced this issue for the past year. Sophos support has been troubleshooting with no success although the firewall is rebooted immediately after the issue starts. Unfortunately this is a retail environment and customers are waiting and…
  • End-Clients - network connection temporarily interrupted

    Hi all! We manage DHCP and DNS for the end devices via the XG310. Since last week, the Internet connection of the clients is sporadically interrupted. The end devices are correctly assigned IP addresses and DNS by the XG. Neither nslookup or ping…
  • Disable traffic shaping for user based rules

    Hey Guys, I have Sophos XG with two internal Zone A and B and WAN zone for internet access. To access internet, users in Zone A required to authenticate and also proper traffic shaping policies are applied for their internet access. I also want to authenticate…
  • Tuning Proxy and Bridge mode

    Hey guys. I wanted to know about best practices for using Sophos in bridge mode. I have little basis in this matter and ask for help from those more experienced in the community. I have an environment with the network segmented into vlans, one for…
  • DHCP Leases - why does it not show a lease count?

    Why does the DHCP Server not show how many leases are used up in a DHCP Pool. There is also no notification if your DHCP Pool is exhausted either. Would be very useful to know if you were getting close to running out. As far as I can see, there is no…
  • DHCP leases - why is it page by page?

    When you look at your DHCP Lease... why is there no option to: a) show more than 20 lines on the page b) export to excel Instead it shows you the leases one page at a time. Not very convenient.
  • Use conntrack to clear connections for certain vlan upon wan timeout. Possible?

    I've been experiencing intermittent issues with our ISP going down the past month. They've all occurred after hours/overnight, so I believe they were actually making repairs due to damage sustained from a partial building collapse a block away. The connection…
  • Dynamic DNS for Namecheap Registrar

    Is this information still accurate? Dynamic DNS - NameCheap It doesn’t seem to work for me on v19.5 also, is there a way to trigger the DDNS update (maybe through CLI) so I can test multiple settings while I get the right one? Thanks!
  • WAN access to few VLAN on backup link

    Hello all! I have a Sophos XGS firewall configured with one LAN and two WAN interfaces. The two WAN links are configured in failover mode, the backup link being activated when the primary one goes down. The backup link has limited bandwidth. I need…