Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Block computers from updating windows

    I have created a rule and applied it to a policy but still not blocking. I have attached screenshots of the rule i created and the policy i applied it in.
  • Intrusion Prevention (IPS) high cpu usage - Snort

    Hello, in our company we got about 60-80 users. Each department got his own vlan running over one port. XGS2100 (SFOS 19.0.1 MR-1-Build365) Over the year i was setting up the sopho xg and adding all Firewall rules, like all department are in one…
  • Sophos XGS 4300 application control can't block specific games like mobile legends

    Sophos XGS 4300 application control can't block specific games like mobile legends. Below are the screenshot of the configuration: Thank you,
  • Category of ip address of Anydesk

    After applying Decrypt and scan https, anydesk not working, can u pls provide the Category of ip address of Anydesk, also explain the configuration method
  • Internet and Reporting issue with XGS87

    I have encountered a remote case with this firewall, the setup and issue is as follows: Firewall model: XGS87 Firmware: SFOS 19.0.1 MR-1-Build365 This is a new firewall that we have deployed. Before installing this firewall the customer faced no…
  • No anti updates for nearly 24 hours

    Hi folks, I started investigating why the XG115W was showing high CPU load, normally around 5%, but now showing over 20% for extended peraiod. I checked the ATP, Avira, Sophos AV and Sophos anti spam, All but Anti spam last updated early yesterday…
  • How to block Squid Proxy using Application Control?

    Hi guys, How to block Squid Proxy using Application Control? Few applications like Hoxx VPN use Squid Proxy over port 80/443 to evade detection. Regards
  • connection with bad ip address

    hi, if i have sophos XGS or XG and from lan my users start making connection with bad reputed ip address. then can firewall block it??? ATP is same or it is different? can SOPHOS XG/ XGS also consult some IOC Feed ???
  • application filter events

    Hey, since we installed Sophos XG we are getting a loads of app filter events regarding GaduGadu Messenger application. Strange is that this traffic is comming from almost all users and its like 100-1000 events per few minutes. Ofcourse nobody is actually…
  • How to write custom IPS signatures for blocking applications?

    Hi guys, How to write custom IPS signatures for blocking applications? I have found a few VPNs which are not on the application control list and I would like to block them. Regards
  • "Malware 'Unscannable' was detected and blocked in a download" Every Minutes

    Hi, i've got this message every minute since yesterday. Have you got a any idea ?
  • Malware 'Unscannable' was detected and blocked / *ALERT* Sophos XG Firewall - HTTP virus detected

    Hi everyone, We are getting thousands of alerts from our Sophos XG at the moment, and with the below error alert ID and message: Any possible causes of this? Alert ID: 8001 Message: Malware 'Unscannable' was detected and blocked in a download…
  • Sophos Blocking www.msftconnecttest.com

    Seems as of this morning Sophos XG is blocking the connection page for the msftconnecttest.com anyone else have the same issue? Kent.
  • TikTok Application Control

    Helo I realy dont know how sophos still dont have an TikTok App Control. This app its terrible for productivity and bandwidth. Can you please add TikTok to Application Control? How can i block this app?
  • XG Custom IPS Signatures: Proper Syntax/Capabilities/Usage Question

    So, while setting up IPS on the system, I want to *block* the usual badness including scanners, etc. However, I have regular vulnerability scanning done by US DHS/CISA as part of their Cyber Hygeine program, and they scan regularly. As such, using scanner…
  • Agrab

    Hi, Im starting to get "SCAN Zgrab Scanning Attempt Detected" alerts, I understand who would use these, however how do I stop the alerts as they are ~+ Im sure
  • Block Youtube

    Good day I have a challenge with blocking youtube. Initially the rule was working fine and all of the sudden users are able to access youtube. i can block other site but youtube keeps working. i have just upgraded the sophos firmware to SFOS 19…
  • Exchange 0-Day CVE-2022–41040 and CVE-2022–41082, how to check if rules are including the mitigation?

    There is a critical 0-Day exploit for Exchange already being exploited, which is pretty much the same as the "ProxyShell" vulnerability in March. How can I check if the mitigation is already working with Snort or IPS rules? https://gteltsc.vn/blog…
  • Regarding adults, contained in the application category

    Dear Team, As we checked and tried to deny some adult-containing sites on Sophos firewall, with the help of a website, we were able to deny that website, but in the application category, we were not observing any adult-related application, so kindly check…
  • Error Message-Couldn't Update the IPS Status

    So I have IPS protection turned on as shown below: I know that the pattern is updating as shown below: So I have 2 questions. 1. Shouldn't the 'Time of signature update' change dates when IPS and Application signatures are updated? Mine doesn…
  • application filter and web filter

    Hi, In lan network some user need wetranfer access but due to data privacy we dont give to share data upload access only download access so kindly give solution to resolve. model-XG210 version-18.5.4 Thanks Satya
  • Sophos Firewall: v19.0 MR1: IPS Update Question

    Hi, Not sure if this is a cosmetic issue, or something that needs further investigation - the IPS signatures are being reported in one part of the GUI as being old, but yet updated in another screen. Here it's showing Aug 26th But in this…
  • Connections time out when IPS enabled (sporadically)

    We have noticed that connections are sometimes interrupted for a period of 5 minutes. It is then not possible to establish new connections (external / internal) via Sophos. This happens 1-2 times per day and always at a different time. I went through…
  • Incorrectly Identified Applications - iCloud relay

    Hi, How do I report application traffic that is incorrectly identified - The below is being reported as personal network storage, when it's for iCloud private relay, and should therefore (I would ahve thought) be classified under proxy services…
  • IPS updates - old issues returning

    Hi folks, over the last week or so I have noticed previously fixed issues with applications being incorrectly classified returning in my daily reports. Manual proxy surfing and thunder VPN. Why are these previously resolved issues appearing, does…