Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • WAN link going down in Sophos XGS 3100

    We have two lease line links configured on Sophos XGS 3100 firewall out of which the link of one of the lease line link goes down automatically after every 3-4 hours that too after changing weight of lease lines or changing fail over rules. Looking for…
  • UDP Timeout vs UDP Timeout Stream

    Hi, We're getting one-side of calls randomly going silent. The default values of my XG2300 are UDP Timeout 30 UDP Timeout Stream 150 I read I should increase the timeout to 150, but should I make them match? increase both 5x? I don't understand…
  • XG210 HA ver. 18.5.x to 19.0. migration

    Dear all, a customer of mine has 2 XG210 in HA mode (Active/Passive) that are running with the firmware version 18.5. I have to upgrade the HA to the version 19.0 and I'd like to know if I can upgrade/migrate the firmware without un-mounting the HA…
  • FW19 country blocking

    Hello, i create a firewall rule with this manuel https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/FirewallRules/FirewallRulesCountryBasedRuleCreate/index.html but they doesn´t work…
  • Sophos XG API DHCPServer does unexpected

    Hallo Community, i am working on some powershell scripts against the XG APi, when i came across this strange behaviour i do not understand. I am trying to setup a DHCP Server via the API, everything is nicely wrapped in powershell class that's why…
  • OSPF not enabled on interface

    XGS107 (SFOS 19.0.0 GA-Build317 I have OSPF configured and working on another XGS 107. I have dynamic routing enabled in ADMIN>Device Access.> LAN, I am using Port 2, which I have changed to LAN. Under Information OSFP > Interface it shows…
  • TCP responses from a website being dropped by firewall

    Hi, I'm having some trouble with a medical device uploading its results to a web server where it seems the 'return' traffic that should match the HTTPS session to the website is being dropped by the firewall. Basically the device gets plugged in, then…
  • XG310 19 HA Active Active & RED tunnel failover

    Hey folks, I have 2 XG 310 in an active-active HA. When failover occurs (Primary goes down), the RED tunnel goes down and there is no failover for the RED tunnel. I need to disable and re-enable the RED tunnel... Is it the correct behavior in…
  • Sophos SG135 w. SFOS v19 AP100 inactive since 17.5

    Hello, I have problems updating to v19. As soon as I install the v19 update, my AP100 (3 pieces) remain inactive (1 ROOT 2 MESH). Only the ROOT emits WiFi despite the inactive message. As soon as I go back down to 17.5, everything is active again and…
  • Sophos XG 330 suddenly shuts down for 5 minutes, then up again. please help

    Hi Everyone, I have a sophos XG 330 (SFOS 19.0.0 GA-Build317), every afternoon almost always at 4 in the afternoon my sophos lan, wan and dmz ports shuts down, no blinking lights on all ports then suddenly it opens again. what seems to be the reason…
  • The renewal of your Heartbeat intermediate certificate has failed

    My HA XGS136 cluster is experiencing this issue with heartbeats: I get an error alert in Sophos Central The renewal of your Heartbeat intermediate certificate has failed Looking in the heartbeat log I can see failures. tail /var/tslog/heartbeatd…
  • Need help on Sophos XG 310 17.5 to 19.0 upgrade

    Hi all, My Sophos XG 310 running on 17.5 need an upgrade to 19.0, is it safe to do so? As I read comments on Sophos community I have seen a lot of issues faced including configuration flush out and device brick by other users. Thanks in advance…
  • DNS Not Working through IPSEC Remote Access

    Hi, I got a Remote Access IPSEC working on an XGS2300 (v19). It worked but was unusably slow. Sophos support suggested I disable "Use as default gateway" and explicitely add resources VPN clients could see. I want them to see the entire LAN, and the…
  • How to enable a custome v19 GA build with Kernel Address Sanitiser enabled

    How can we enable a custome v19 GA build iwth Kernel Address Sanitiser on sophos XGS version firewsall?
  • PPPoE connection on XGS 2100 SFOS 19.0.0 GA-Build31 - slow page loading

    Hi, I have problem with pppoe connection which I don't know how to solve MTU 1492 MSS 1452 no web policy no ips no DoS tried changing port (on port 2 connection was terrible) Problem is that pages are loading slow, after I press "enter…
  • No Upgrade to 19 available

    After we upgraded our sophos xgs / xg firewalls to SFOS 18.5.4 MR-4-Build418, i dont get the offer to install v19 ?! Trying to download it and install it manualy results in the questes if i am sure to do that because the system is booting in factory default…
  • Issue with Mail protection and Microsoft exchange self-signed certificate.

    We're using XGS126 (SFOS 19.0.0) with active Mail protection subscription and our mails are hosted on on-premises Exchange server. We had issue, that we got error message because Sophos couldn't verify certificate for our internal mail server and mails…
  • Internet pages suddenly no longer work 502

    Hello, since today suddenly several internet pages do not work anymore. The browser gives the error message: HTTP ERROR 502 The page is e.g. https://www.ista.com/de/ Firewall is a XG115w (SFOS 19.0.0 GA-Build317 Do you have a solution? Thanks…
  • [Remote access IPsec] Can't establish a connection-IKE port not opened (3 IPsec tunnels already operative)

    Hi everybody, We're facing this weird issue on a Sophos XGS 3300 (SFOS 19.0.0 GA-Build317) when we try to connect from remote site via Sophos Connect, I tried to unlock by hand the ports, remake the policy but nothing happens, even called to the ISP…
  • XGS107w Firewalls blocking ESET Updates and LiveGrid

    Hi, We recently deployed a couple of XGS107w units (SFOS 19.0.0 GA-Build317) and have been unable thus far to configure them to allow client devices to connect to ESET servers for updates and LiveGrid. The only filtering enabled on these routers are…
  • VPN client receive wrong IP address

    Hello, i am experiencing strange behavior of VPN clients after my A/P cluster XGS to v19. In VPN ssl global setting i have subnet 10.200.250.0/22 for my clients. But rundom VPN clients receive ip 10.200.248.xxx i have try to re-aply VPN ssl global…
  • Syslog format SFOS 19.0

    Hello! There is a doc to describe new syslog settings for SFOS 19.00? Here is real syslog from Web Content policy: device_name="XG210" device_id=XXXXXX log_id=050901616001 log_type="Content Filtering" log_component="HTTP" log_subtype="Allowed" priority…
  • XG550 (SFOS 19.0.0 GA-Build317) : problem with Web filter, RDP connection block after upgrade

    Hi, after upgrade from SFOS 18.5.3 MR-3-Build408 to SFOS 19.0.0 GA-Build317, without changes to the policy, we have a problem with connections in vpn ssl, RDP connections (tcp 3389) are blocked. T he logs indicate that RDP connections are blocked by…
  • Pre-shared Keys Changing

    Hi, I have a doubt about a pop-up in the vpn configuration menu. My current firmware is: SFOS 19.0.0 GA-Build317 When i click to save button on the vpn configuration, i have the same pop-up: "the change will update the pre shared key of the all connections…
  • VPN Speed - SFOS 18.5x vs. 19

    Hi all, I still struggle with going from 18.5.2 to 19.0 on my XGS116 as there are too many issues but I tested v19 as VMware appliance. In my test scenario I used SSL VPN and checked up and down speeds from the remote client. According to the first…