Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • SAP system not accessible after deploying SOPHOS firewall

    Good day We have deployed a Sophos firewall on a network, there was a cisco router and we have replaced the cisco router. After deploying the firewall the SAP system is not accessible on the local area network .. We have a SAP server in the LAN…
  • Need help with routing LAN to WAN

    Do you have an article to help better understand routing on Sophos Firewall? I want my LAN to communicate with my WAN.
  • Couldn't delete user. A firewall rule, VPN connection, web policy rule, or SSL/TLS inspection rule exists for this user.

    Our company own a sophos firewall xgs ( XGS3300), I try to delete user from 'Authentication' page but it failed, i able to disable the user account, but unable delete the user account. but some account i able to delete. i appreciate if there is…
  • UTM DNS > Global > Allowed Networks -- how to reproduce in SFOS?

    I am working on migrating functionality from UTM to SFOS on XGS3300 hardware. This organization subscribes to this DNS filtering service: https://www.cisecurity.org/ms-isac/services/mdbr In the UTM, it was easy to bottleneck DNS queries so they are…
  • Firewall default IPS policies

    I found https://community.sophos.com/sophos-xg-firewall/f/discussions/110856/default-ips-policies/397166?focus=true, didn't help. Sophos pre-packages some IPS policies by default. Without having to go through each of them with a fine toothed comb, is…
  • Assistance Required: Binding Static IP to Local IP Address

    static IP 203.122.47.42 on port 84 is showing as closed. We need to bind this static IP to the local IP address 10.0.1.134 . Please assist with this at your earliest convenience. Thank you.
  • How to get Firewall Rule ID from XML export file

    When creating an XML export of FirewallRule via Backup & Firmware -> Import export what is missing in in the XML is the Rule ID. How to get this ID? Or can this be retrieved via API request? greetings, August
  • IPv6 Gateway constantly failing

    I need some help to understand why this firewalls IPv6 gateway is constantly reported as failed. It's XGS126 with SFOS 20.0.1 Because of that Gateway errors I reconfigured it from being an active gateway to a backup failover gateway only. I have…
  • FIREWALL RULE OVER VPN (WAN-VPN)

    Does anyone here encounter no access on yahoo even on whitelist? All site is accessible expect for yahoo sites. Anyways I'm doing VPN-WAN rule from XGS107 (SFOS 18.5.2 MR-2-Build380) to XG230 (SFOS 18.5.2 MR-2-Build380).
  • dns server on XG106

    hello, Can I have a detailed procedure to configure my sophos xg106 as a dns server ? Thanks
  • Problems with Veeam B+R 12.1 and SFOS 20.0.2 MR-2-Build378 - failed to create NFC download stream

    Hey Folks, we rolled out a XGS126 in our Branch yesterday (before SG125) and we cannot get Veeam to work backing up our Branch VMs. The Branch is connected via IPSEC VPN Tunnel to our Datacenter (Sophos SG310). I already found the older thread Veeam…
  • Web Server on VLAN

    Hello Everyone, I am having a little configuration issue with my web server on a VLAN. All my VLANs have internet access but I can't seem to access my web server from outside my network. Can anyone post an example firewall rule from Public IP to VLAN…
  • Sophos XG - Dynamic rule / object group members used in SOAR automation?

    I am not planning to use Sophos Central, my XG firewall is standalone. I have a fairly complex security stack setup with a separate IDS/IDS and SOAR type system along with a honeypot outside my firewall protected zones. I would like to automate whenever…
  • Enable Routing for public IP on the Lan Interface

    Hello everybody! Right now I have the situation where I want to have multiple public Servers behind a sophos virtual firewall. For the Sophos i have a seperate public IP. I have a public IP Subnet for the servers that is routed via the public IP of…
  • Create user sophos from API Laravel

    how to create user sophos from laravel API. i'm success create user with API postman, but when i'm implemented in laravel. User not created. Please help me this my script in laravel public function sophos() { try { $url = "">192.168.7.1…
  • Unifi USG behind Sophos XG - vlan config

    Hi, my current network looks like this. This is a double NAT scenario but works quite well. Now I got a Unifi USG for testing purposes. I'd like to add it between the Sophos XG and the Unifi Switch. The Sophos should keep on managing DHCP, DNS…
  • VLAN firewall best-practices / Mode bridge, gateway mode

    Hello, we got 2 new XGS450-firewalls. Currently the configuration is blank. The firewall should manage the vlan traffic. We have 3 branches. They are connected with a cisco mpls-network. Our internet-firewall in the mpls network: Should be…
  • Merging of two incoming lines.

    I have two lines on firewall one is of internet line and one is of local line on which a specific website works. When we search that specific website that 2nd line should come into picture, but currently both the line are active but that website is not…
  • External web site does not open.

    Hi experts, I have an external web site hosted in the AWS, and the DNS domain name is registered in my local DNS server (Windows 2019 with AD and DNS). I have configurated the DNS options in Sophos XGS as shown below. The website does open for internal…
  • DHCP Static IP mapping for same client multiple networks - FW 20.0.1

    Hello, I refer to RE: DHCP Static IP mapping for same client multiple networks? With the update from SFOS 20.0.0 GA-Build222 to SFOS 20.0.1 MR-1-Build342 the Sophos system dhcp conf-generation-method has been set to old again: console> system…
  • SNMP Collection - Sophos XG 19.5

    hello, I noticed that when I execute the `snmpwalk` command on the OID `.1.3.6.1.2.1.31.1.1.1.18` (ifAlias), the result comes back empty. When I execute the OID `.1.3.6.1.2.1.2.2.1.2` (ifDescr), it returns the interface name. For example: eth7. …
  • Outbound UDP port 443 blocked

    We have a Sophos XG135 firewall running SFOS 20.0.1 MR-1-Build342). We have a cloud 8x8 VOIP phone soultion which is having intermittant audio issues. We have been asked to run their network diagnostic tool which is reporting back UDP port 443 outbound…
  • Route IPv6 to DMZ

    Hi there, we have a /64 subnet (with gateway) and a /56 assigned by the ISP. No PD in place. I've assigned an address from the /64 subnet together with the gateway to the WAN interface, which is now reachable via IPv6. I'd like to assign IPv6 Addresses…
  • Linked NAT rule for LAN to LAN traffic?

    Hello all, I have inherited a firewall that has linked NAT rules for LAN to LAN type rules. Is there any need for them (I don't think so as really only required for LAN to WAN), and would it hurt anything if I just left the NAT rules? Thanks.
  • Web Pages Slow to Load

    Referencing this previous post: Webpages SLOW to load That post is over 7 years old and locked, so I am posting here. I recently started having this same issue...Web pages take 30+ seconds to load for all users on network A number of coincidental…