Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Whatsapp Allow chat and sent files

    Hello everyone, so I create new role and allow whatsapp application but it was allow chat only so I add exception in web control with domain of whatsapp.com to be allow so now all OK and they can send pictures, videos and files This network open…
  • Web Browser Based VPN Deny

    Hi; I use xgs4300 in the HA structure on which I spend a large network traffic. many app and web filters are applied on the device and more than 1500 users with 6 different DC authentication go online with user-based rules. I have created many policies…
  • ChatGPT rules to allow access.

    Palo-Alto added App-IDs for their firewalls to allow the use of ChatGPT https://www.paloaltonetworks.com/blog/2023/05/securing-and-managing-chatgpt-traffic/ I checked our XG and found nothing. So if anyone has an idea how I can set up rules to allow…
  • Intrusion prevention alert (Critical)

    Hello, I have this alert today: intrusion prevention alert, but i don't know how to check or to diagnose this
  • IPS SERVER-WEBAPP ThinkPHP 5.0.23/5.1.31 CVE-2018-20062 Remote Code

    I have many IPS reports of this type: "IPS SERVER-WEBAPP ThinkPHP 5.0.23/5.1.31 CVE-2018-20062 Remote Code " I don't understand if these attempts are effectively blocked, then in general do you have any recommendations to mitigate this vulnerability?
  • Firewall XGS 116 Enable to configure some rules

    Good morning, I have a problem regarding the configuration of certain rules at the Sophos Firewall level. It is impossible for the local partner to filter me on all smartphones connected to the network, a ban on all applications except Microsoft applications…
  • What ist the benefit of IPS, Zero-Day Protection, ATP and web filtering without deep packet inspection on TLS sessions

    stupid question, I know, but honestly: what is the benefit of the Xstream protection when you decide not to break TLS sessions at all (besides mail filtering)? Will someone earn any higher protection level with all these features activated without breaking…
  • Microsoft Teams Call Disconnecting often

    Dear all, We are having XG450 Firewall in High Availability and the we have the latest firmware installed... We are facing Microsoft Teams call is disconnecting intermittently under our Sophos XG450 Firewall. I tried all the following settings for the…
  • Using Application Filtering Lists for Web Policys

    Hallo @all, regarding https://community.sophos.com/sophos-xg-firewall/b/blog/posts/generative-ai-policy-enforcement-with-sophos-firewall is there any way to use the new application category for the web policys? Application filtering only allowing allow…
  • XGS ATP Alert (No Host Name or Threat)

    Today our XGS started reporting ATP sources blocked without a Host Name, IP, or Threat. There is also no information under Monitor & Analyze > Reports > Network & Threats: Advanced Threat Protection How do I go about tracing down the issue? …
  • IPS update pattern drop packets

    Hi, we have a SFOS 19.5.3 MR-3-Build652 and since few weeks, when the ips update the patterns, the sophos firewall drops all the packets for 30s. It will never do that before . Is this a bug ? Thanks Regards,
  • Can we block chrome or any browser vpn extensions

    want to block browser based extension vpn
  • Allow FB Two-Factor Authentication Only

    Our company allowed Facebook Messeger as messaging app but we are having hard time to allow page of Facebook two-factor authentication page without allowing the whole Facebook website.
  • IPS update appears to break fb videos.

    Hi folks, last night (my time) the IPS update (18.21.02) appears to have broken FB videos and the login screen. If I use my hotspot the FB access works correctly. Ian
  • PSIPHON - how to block the application version?

    Hi folks, I have been working on another thread where a user has not ben able to block PSIphon. I have been able to block PSIPHON on all web access from ipads, iPhones and MBP. The issue is how to block the PSIPHON application theat you download…
  • Bypassed SOPHOS

    1. I created a Decryption profile name DELETE and choose reject on compression and all other option. certificate error block all algorithem and authentication all block block action reject. 2.Applied to my device ip as source network to WAN all…
  • RE: Blocking Tiktok via Firewall Application Control and Endpoint Application and Web policies

    Hi Glenn, here are some other items that are along the same lines as the tiktok issue. Unable to block adverts on web pages. Ian
  • Application Control Policy and User

    We have active application control at a customer. Different application rules were created for this. For example, a rule in remote maintenance applications such as B. Teamvier are allowed and a rule which allows file transfer services (e.g. Dropbox).…
  • Ips not working on home edition

    Hi All I'm using sophos home addition Since four weeks i'm struggle to Make it work Ips But no luck e My hardware is Intel i7 8700 cpu 8gb Ram with Intel i350 nic Firmware 19.5.3mr Any help will be appreciated Thanks
  • WEb ExPloit PRotecTion

    Is EXPloit Protection, work Out of the Box? Now I Find ‘ Detect and prevent exploits (IPS)’. lantoWan- general policy Which I’ve enabled. Is That the full extent of it, and A feature that Works under the Hood? Is There Any solid inFormation in XG, and…
  • Changing ATP Settings: "The operation will take time to complete. The status can be viewed from the "Log viewer" page"

    Whenever I click Apply in ATP, I can see the spinning circle and after some time the message " The operation will take time to complete. The status can be viewed from the "Log viewer" page ". It does not matter if I change somethin, add hosts or whatever…
  • Branch site not connecting to share point and one drive

    Good day I have a Sophos firewall XG 310 V 19.01, The firewall is at the HQ, and there are MPLS sites connecting to the head office. we are using Microsoft 365 The problem is, we are failing to open Sharepoint and Onedrive from the MPLS sites. But…
  • Identify and control applications (App control)

    I'm having an issue with the Sophos Application Control in regards to TikTok. Yesterday I read several Sophos articles regarding this and it seems like I am beating a dead horse. At first, I hoped that an application filter would block. Apparently this…
  • IPS rule LAN-LAN

    Hi everyone, I have two firewalls connected by a dark fiber on a SFP port, the two main LAN networks are 192.168.1.0/24(FW1) and 192.168.0.0/24(FW2). In both firewalls there is a rule to allow all traffic between the two subnets, so the source and destination…
  • Build-In IPS policies: Differences?

    Because the online-help is pretty useless regarding this question: What is the difference between the policies on top and the last ones (in small letters)? What are better? Why double build-in?