Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • SET DNS Preference for each gateway

    We have multiple ISP gateways per XG. Is there a way to set DNS server preferences for each particular gateway? WHY? I've added NextDNS as an additional layer of security and for analytics to function properly for each profile I need DNS servers…
  • Can I define both vlan and per-user bandwidth in Sophos Firewall?

    Hi , Can I define both vlan and per-user bandwidth in Sophos Firewall? For example , when setting a limit to traffic shaping vlan on Fortigate ; per-ip shaping could also be done.
  • Combining LAN Ports / VLANS / DHCP

    Hi everyone, I was wondering if anyone can help. I have the follow: An XGS2100 I need to connect 4 separate switches into it. I need the 2100 to: 1. Act as a gateway for 5 different VLANS across the 4 ports irrespective of when the gateway…
  • MIB OIDs not supported for Zabbix - XG FIREWALL SOPHOS

    I've tried using the two templates available in the zabbix repository, but without success. Both models do not support OIDs. I manage to communicate my firewall with Zabbix by SNMP, but it is not possible to communicate data because we don't have a template…
  • Unable to obtain IP address from DHCP created for VLAN interface.

    Hi! Unable to obtain IP address from DHCP created for VLAN interface. The L2 switch is a NETGEAR GS308T and is trunked to the Sophos XG Firewall. I have an access point connected to the GS308T and cannot get an IP address via DHCP on my iPhone or…
  • My vlan's get can't an ip address or internet access via DHCP relay (windows server 2022)

    Hello, This is my L2 schéma and L3. I have 2 xg 115 firewall, a sophos switch. I also have a windows server 2022 how have a DHCP server. I want my pc's to get an internet access and to get their ip form my windows server 2022. I first tried…
  • Client DHCP renewal is blocked by XG106 firewall

    We have experienced this issue for the past year. Sophos support has been troubleshooting with no success although the firewall is rebooted immediately after the issue starts. Unfortunately this is a retail environment and customers are waiting and…
  • End-Clients - network connection temporarily interrupted

    Hi all! We manage DHCP and DNS for the end devices via the XG310. Since last week, the Internet connection of the clients is sporadically interrupted. The end devices are correctly assigned IP addresses and DNS by the XG. Neither nslookup or ping…
  • Disable traffic shaping for user based rules

    Hey Guys, I have Sophos XG with two internal Zone A and B and WAN zone for internet access. To access internet, users in Zone A required to authenticate and also proper traffic shaping policies are applied for their internet access. I also want to authenticate…
  • Tuning Proxy and Bridge mode

    Hey guys. I wanted to know about best practices for using Sophos in bridge mode. I have little basis in this matter and ask for help from those more experienced in the community. I have an environment with the network segmented into vlans, one for…
  • DHCP Leases - why does it not show a lease count?

    Why does the DHCP Server not show how many leases are used up in a DHCP Pool. There is also no notification if your DHCP Pool is exhausted either. Would be very useful to know if you were getting close to running out. As far as I can see, there is no…
  • DHCP leases - why is it page by page?

    When you look at your DHCP Lease... why is there no option to: a) show more than 20 lines on the page b) export to excel Instead it shows you the leases one page at a time. Not very convenient.
  • Use conntrack to clear connections for certain vlan upon wan timeout. Possible?

    I've been experiencing intermittent issues with our ISP going down the past month. They've all occurred after hours/overnight, so I believe they were actually making repairs due to damage sustained from a partial building collapse a block away. The connection…
  • Dynamic DNS for Namecheap Registrar

    Is this information still accurate? Dynamic DNS - NameCheap It doesn’t seem to work for me on v19.5 also, is there a way to trigger the DDNS update (maybe through CLI) so I can test multiple settings while I get the right one? Thanks!
  • WAN access to few VLAN on backup link

    Hello all! I have a Sophos XGS firewall configured with one LAN and two WAN interfaces. The two WAN links are configured in failover mode, the backup link being activated when the primary one goes down. The backup link has limited bandwidth. I need…
  • Feature Request: VLAN moves

    I would like to see an easy way to move vlans to another port. This will help in moving a heavily used port from one port to another without having to delete the vlan and DHCP scope and recreate it. This would speed up moving vlans across ports. …
  • Sophos XGS 136 - VLAN Problems

    I am newbie currently testing a Sophos XGS 136 Firewall, The basic setup is working. We have a Cisco 3850 Core Switch with 4 VLANS and only the VLAN that the firewall is connected to is working. Traffic from other VLANS is not working and can not ping…
  • Bridge Wireless Network on Sophos REDW to lag VLAN. Possible?

    Hi all, is it possible to bridge a Wireless Network to a vlan interface from the firewall itself? The traffic should not leave the RED itself in their lan interfaces. Can this only be done with using separate zone and bridge this separate zone with…
  • Sophos Firewall - Gateway down but Interface Connected

    Hi all, I rarely work with Sophos Firewalls and haven't ever had to do much on them before, but having recently logged in to one I found that on the 'Control Centre' page that 'Interfaces' is highlighted orange. When I then select 'Interfaces' it…
  • Phones behind XGS lose connection to Cloud PBX every hour

    Hello all, we have a problem with a new XGS126 and connecting phones to a cloud PBX. Yesterday we have exchanged a UTM for a XGS. Until then the telephony worked without problems. Since the swap, the phones (Yealink) lose connection to the PBX (Starface…
  • Connecting CISCO CBS350 Switch to Sophos XG 125 firewall

    Currently I have a Cisco SG300 connected to my Sophos XG125 Firewall and everything is working well. SG300 is running as a L3 switch and its connecting to the firewall using a trunk port. I have VLANS as well and intervlan routing is working well. The…
  • Slow/Freezing SMB Traffic over Sophos XG Gateway Opening

    Hello, since adding the Sophos XG as man in the middle / gatway to our network, we have speed issues more or less, specially over SMB. At moment the XG is connectet over 1 gig port to the main switch, the main switch has sub switches, at main switch…
  • Why is required bridge interface

    Hi All, Can anyone explain in layman's term what is the use of bridge interface/Mode in Sophos XG firewall. In which scenario do we use bridge mode also what is the benefits of it. Thanks
  • No Namecheap service provider available when adding new Dynamic DNS

    There is no option for namecheap. Why is this?
  • Sophos XGS 107 firewall - do not relay ICMPv6 RA with global prefix to LAN

    Hi, I was investigating problem in RE: Sophos XGS 107 firewall - do not relay IPv6 DHCP to LAN now I analyzed network traffic and have some insights. I see ICMPv6 packets with Router Advertisement (134) with Prefix information coming into my LAN from…