Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • How to enable a custome v19 GA build with Kernel Address Sanitiser enabled

    How can we enable a custome v19 GA build iwth Kernel Address Sanitiser on sophos XGS version firewsall?
  • PPPoE connection on XGS 2100 SFOS 19.0.0 GA-Build31 - slow page loading

    Hi, I have problem with pppoe connection which I don't know how to solve MTU 1492 MSS 1452 no web policy no ips no DoS tried changing port (on port 2 connection was terrible) Problem is that pages are loading slow, after I press "enter…
  • No Upgrade to 19 available

    After we upgraded our sophos xgs / xg firewalls to SFOS 18.5.4 MR-4-Build418, i dont get the offer to install v19 ?! Trying to download it and install it manualy results in the questes if i am sure to do that because the system is booting in factory default…
  • Issue with Mail protection and Microsoft exchange self-signed certificate.

    We're using XGS126 (SFOS 19.0.0) with active Mail protection subscription and our mails are hosted on on-premises Exchange server. We had issue, that we got error message because Sophos couldn't verify certificate for our internal mail server and mails…
  • Internet pages suddenly no longer work 502

    Hello, since today suddenly several internet pages do not work anymore. The browser gives the error message: HTTP ERROR 502 The page is e.g. https://www.ista.com/de/ Firewall is a XG115w (SFOS 19.0.0 GA-Build317 Do you have a solution? Thanks…
  • [Remote access IPsec] Can't establish a connection-IKE port not opened (3 IPsec tunnels already operative)

    Hi everybody, We're facing this weird issue on a Sophos XGS 3300 (SFOS 19.0.0 GA-Build317) when we try to connect from remote site via Sophos Connect, I tried to unlock by hand the ports, remake the policy but nothing happens, even called to the ISP…
  • XGS107w Firewalls blocking ESET Updates and LiveGrid

    Hi, We recently deployed a couple of XGS107w units (SFOS 19.0.0 GA-Build317) and have been unable thus far to configure them to allow client devices to connect to ESET servers for updates and LiveGrid. The only filtering enabled on these routers are…
  • VPN client receive wrong IP address

    Hello, i am experiencing strange behavior of VPN clients after my A/P cluster XGS to v19. In VPN ssl global setting i have subnet 10.200.250.0/22 for my clients. But rundom VPN clients receive ip 10.200.248.xxx i have try to re-aply VPN ssl global…
  • Syslog format SFOS 19.0

    Hello! There is a doc to describe new syslog settings for SFOS 19.00? Here is real syslog from Web Content policy: device_name="XG210" device_id=XXXXXX log_id=050901616001 log_type="Content Filtering" log_component="HTTP" log_subtype="Allowed" priority…
  • XG550 (SFOS 19.0.0 GA-Build317) : problem with Web filter, RDP connection block after upgrade

    Hi, after upgrade from SFOS 18.5.3 MR-3-Build408 to SFOS 19.0.0 GA-Build317, without changes to the policy, we have a problem with connections in vpn ssl, RDP connections (tcp 3389) are blocked. T he logs indicate that RDP connections are blocked by…
  • Pre-shared Keys Changing

    Hi, I have a doubt about a pop-up in the vpn configuration menu. My current firmware is: SFOS 19.0.0 GA-Build317 When i click to save button on the vpn configuration, i have the same pop-up: "the change will update the pre shared key of the all connections…
  • VPN Speed - SFOS 18.5x vs. 19

    Hi all, I still struggle with going from 18.5.2 to 19.0 on my XGS116 as there are too many issues but I tested v19 as VMware appliance. In my test scenario I used SSL VPN and checked up and down speeds from the remote client. According to the first…
  • XG SFOS 19 Mail Relay MTA route to host with different port

    We have an XGS cluster and we want to use the Email protection module in MTA mode. When entering a static route to a mailserver, the emails are normally sent over port 25. When using the Spam protection the normal procedure for blocking non existing…
  • Couple SSL VPN questions

    Hi, Ive got an XG3100 on SFOS 19.0.0 GA-Build317 I'm a little confused on two things on SSL VPN users and would be brilliant to have clarification as no doubt im being a numpty. Some information ive changed for security like domain.local isnt the…
  • Logviewer sometimes no origin/destination-port

    Good day, at the moment we have a lot of shity traffic going on , mostly from Russia and its lovely friends . Right now I ´ ve seen that there are p ackages without origin-port and destination-p orts in the Log Viewer . Whys that ? Never had this…
  • XG Firewall SNMP to UNMS/ UISP

    I am attempting to add my XG firewall to Ubiquiti's "UISP" which used to be called UNMS. The UISP will add 3rd party routers and switches that has SNMP. It wants the public IP and SNMP Community string. Ive tried a few things such as the name as…
  • Sophos SSL VPN Configs not generating on XG230 (SFOS 19.0.0 GA-Build317)

    Hello all! Anyone ever had an issue where in the user portal when downloading an SSL VPN Configuration you're clicking on "Download for Windows, macOS, Linux" and what's downloaded is a 1 KB ovpn file. When opening this file in notepad it displays…
  • XGS Fan Noise

    Hello All I know this subject has been brought up before but this is the first time I have purchased one of the lower end models that being a Sophos XGS107w. This has been installed in a quiet office and receiving complaints of the constant humming…
  • IPS Logging

    How does one enable logging (so one can see it in the Log Viewer in the management web interface) of IPS events. Every time I have a IPS problem, I get email notifications but the IPS Log Viewer tab is empty - how can i get it to populate? Regards…
  • Logging to Sophos Central drops (again)

    I reported this during EAP, but it's happened again. I went to Sophos Central to do some reporting and the last three days of logs are missing. It just stopped. Perhaps this was tied to an IPv6 tunnel (gateway) going up/down or something that confused…
  • Admin not available over ipsec tunnel with traffic selectors.

    When setting up ipsec tunnels between various xgs we see an issue where if using tunnel interfaces with traffic selectors we cannot access the admin 4444 page from another office. SSH and ping work fine so the routes are working . If we use site to site…
  • Unifi Guest Portal not working when using VLAN with Sophos XG

    Hallo, we are using XG210 with SFOS19 and a large Unifi setup with multiple switches and access points. Everything works fine. After trying to move the Guest Portal created by Unifi to a VLAN the guest portal login page doesn't come up anymore. Using…
  • Garner Service Dead - XG V19.0 GA

    Hi all, I am running the latest version of Sophos XG (19.0) in a HyperV VM. All has been well since installation some time ago, but suddenly I am having issues with the Garner service, and the XG is reporting Service LoggingDaemon stopped. No config changes…
  • no access from wan after upgrade to fw ver.19

    Hi all, I noticed that after upgrading to the newest firmware (19.0), I cannot access the device from WAN. Neither the user portal, not the admin portal, even though they are enabled in the administration - device access. Anyone noticed similar problem…
  • XGFW All Reports are empty.

    My SG330 (SFOS 19.0.0 GA-Build317) has been running for a long time and was recently upgraded to V19. I don't read reports very often, but today I found all the reports were empty. No matter how long you choose . Where might I look to troubleshoot this…