Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • SD-WAN and Normal Firewall Rules

    XG86 Firewall v19.0MR1 TLDR: When i enable SD-Wan for a certain zone to use differente Gateway all other rules on that zone is ignored I have 2 Zone and 2 Wan. First LAN zone use ISP1 and ISP2 as a backup For the Second Zone i need ISP2 default and ISP1…
  • Access system from LAN by usig DHCP ip address

    Dear Sir, I have biometric device which connects to WIFI and IP is released by DHCP in sophos XG 310 firewall. It does not ping to this IP from LAN network, nether i am able to access this device using this dhcp released IP address from browser.. How…
  • Can't reach certain public servers

    I have multiple pieces of software behind my Sophos that try to reach out to their public servers (usually http port 80), but always return an error stating the host failed to respond. In general, the devices behind this Sophos don't have any problems…
  • Unable to access vlans from main network

    I have 2 Vlans on my network, 1 for voip and one for manageing devices such as swithces and accesspoints. until recently i was using a different router and that worked fine however sincce switching i am unable to access the vlans on th email network…
  • Sophos V18.5MR5: What kind of ICMP protocol are enabled in the service Ping/Ping6 in Device Access Tab?

    Hi, i'm working on getting the correct ICMP firewall rules on my Sophos Firewall. For doing this i've created a Local Service ACL Execption rule using the service "Ping/Ping6" for my WAN zone and allowing only some common route we use, excluding the…
  • Pix-Star digital photo frame can't get to the internet

    This is on the XG106w (SFOS 19.0.1 MR-1-Build365) I have a client that has a Pix-Star digital photo frame that can't see the internet when connected to WiFi. I knew something was blocking it but didn't know what, so I had created a bypass rule for the…
  • XGS 136 blocking Dlubal RFEM

    Hi! I'm new here and this is my first post. I'n running SFOS 19.5.0 GA-Build197 and I have an app (Dlubal RFEM 6.02.0045) being blocked by Sophos XGS 136. In Log Viewer, I can not locate any logs related to this blocking. I know that Sophos is…
  • Could not associate packet to any connection.

    I have the XGS 136 firewall, SFOS 19.0.1 MR-1-Build365 , I have a problem connecting the local network to the DMZ . Users get invalid traffic. and the server ( Odoo ) stops responding , and this issue happened more with users who have Laptop HP -15- DY…
  • Strange Firewall rules or something not understood

    My goal is to install a telephony server in the LAN. This server must be accessible from the internet with a number of protocols here (PRO_Starface). To prepare this I created a NAT rule and a firewall rule to access this server from internet. Just…
  • SD-RED network can't reach XG Network

    Hello everyone, I have a problem with a sd-red 60 in transparent split mode, the scenario is: - Tunnel is up and hosts behind red can surf. - From XG I can ping the hosts behind the red and reach remote desktops and everything, but from Red I can…
  • Help! NAT that works on UTM9 not working on SF/XG.

    Hi, hoping someone can help. Apologies for the long post. *** This looks like a repost from another user but for some reason when I logged in to the community recently it set up a new account for me. I am the OP of this thread** ALSO, Although in…
  • Unable to update PS5 games - "Invalid traffic" - conntrack

    I have a problem with our PS5. We are unable to download updates to software. Initially this was failing when it was connected via WiFi using Sophos hotspots. I connected it via a wire and it worked, for about a day. I am pretty sure that my issue is…
  • XG115 Firewall and 1to1 NAT

    Hi There, I’m new in the Sophos world and I have some trouble configuring 1to1 NAT. My case: XG115 Firewall (XG115 (SFOS 19.0.1 MR-1-Build365), 1 Server in the LAN (no DMZ), 1 public address for this Server. I want to access my Server from Internet…
  • Sophos Firewall and SQL Server Management to Azure SQL

    Hi, I have Sophos Firewall v19 and a internally computer that needs to connect to Azure SQL using SQL Server Management tool. If I create a rule that allows the computer outbound on destination ANY service, it connects, great. I want to lock it…
  • Configure two WAN for WIFI zone

    Added second WAN zone network port5 ipv4 192.168.101.2/27 gateway ip 192.168.101.1 SSID new network DHCP Firewall Rule WAN link manager information able to connect Tablet to Wifi and i get DCHP release result block firewall…
  • I can't access internal/external ports

    I have a XGS Firewall in bridge mode behind a Uniif Dream Machine. Sadly the port forwarding rules don't work and i wanted to ask if someone maybe knows why. The XGS is in the 192.168.55.x LAN and the Unifi (my main LAN with all devices) is in the 192…
  • Site 2 Site VPN open but but hosts not reachable

    Hi there I configured a site to site VPN on a XG 115 On the other side we have a Zyxel Firewall, The VPN seems to work, VPN green and connection green. But hosts are not reachable on the remote side. I think it is a Firewall rule missing on the…
  • XG 85 and 105 not resolving specific hostname

    Greetings guys, Hope you all doing well, I'm running Sophos XG 85 and 105 at: XG105 (SFOS 17.5.17 MR-17-Build837) XG85 (SFOS 17.5.17 MR-17-Build837) I have multiple network environments where I use Sophos Firewalls XG 85 and 105. When I try…
  • Configure firewall rules for users object

    Hi every body/ I'm no familiar with XG so much (I have UTM). Is it possible to configure rules in firewall in XG to use "user" or "user group"? The XG gets the user list thru active director. My goal is to create a firewall rule based on users group…
  • 2 wan connections unable to access static ip's on one from main lan but can from outside

    I have 2 wan connections 1 FTTP with 1 static ip and 1 FTTC with 6 static ip's, i have set up some nat rules for the main connection (FTTP) and they are accessable from inside the lan, i have also tried to setup some nat rules for 2 of the 6 ip's on FTTC…
  • Default SSL/TLS inspection rule missing

    Hi there, I recently configured a new XGS3100 active/passive cluster with SFOS 19.5. Everything seemed to be fine, but as I wanted to configure the SSL/TLS inspection (I normally do this as one of the final steps) I realized, that there is missing something…
  • No acess with only ping and smb - vpn ipsec site ti site

    Hi all , Today i have weired problem ! I have vpn ipsec connection between HQ and BO There are few protocols allowed between the two LANS, but all access are initiated from HQ like RDP, Ping or access th share folder (SMB) So everything working…
  • Drop rule shows Accepted traffic in firewall AND proxy.

    Referencing this: https://community.sophos.com/sophos-xg-firewall/f/discussions/125695/bug-drop-rule-reporting-allowed-connection-in-logs And this: https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Logs…
  • XG Firewall Apple TV+ Connection Issues

    Ok, so I decided to give Apple TV+ a try. I am aware of how finicky Apple products can be, but decided to give it a whirl anyway. Perhaps I'm beating a dead horse on this. The first issue was the XG blocking QUIC, once I allowed QUIC, streaming seemed…
  • Local ACL Violation

    Hello, I'm running web server on port 443 in DMZ zone with another service running on port 7xxx. I can browse web page because of waf rule, but I can not connect to service on port 7xxx from WAN, Packet capture show ACL Violation Show…