Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Reimage

    Is SFOS 19.5.2 MR-2-Build624 available as an ISO file? I looked at the website, but I don't see the most recent update. I took a backup of the most recent version from the XG firewall and am now attempting to migrate to XGS and install the image build…
  • strongswan / ipsec - Certificate chain with 3 certificates does not work. X.509 Certificate Chain Files

    Hello to all, I would like to set up an L2TP remote access VPN connection with authentication via certificate. Unfortunately, this does not work if an intermediate certificate is used without having to modify the ipsec configuration via shell. Environment…
  • IPsec traffic no longer in VPN Zone?

    Ok, i`ve just encountered a strange behaviour/phenomenon with the XGS3100 Firewall we are using: Reacting to a ticket that homeoffice connections via IPsec VPN no longer work, i eventually checked the policy tester to assure myself the FW rules were…
  • XG Home Edition won't install update

    I'm running home edition XG 19.0.2 MR2 build 472 ontop of Proxmox. I'm struggling to get the latest update (19.5.2 MR2) to install. it's showing as available and i am prompted to install it on loggig in to the admin portal. it's showing as availble…
  • Clearing Zero-Day Protection log

    Running SFOS 19.5.2 MR-2 on an XG310. In the Zero-day protection section of the Control Center, it shows 0 Recent, 274 Incidents, 330 Scanned. When I click on that, it goes to the Zero-day protection logs, and I get two pages containing a total of 38…
  • XG 106 Firewall Wizard Looping - Want to Restore from USB

    Hi, I am setting up an XG 106 Firewall and it seems to be stuck in an initial setup wizard loop. I will go to login to the firewall again and it sends me through the wizard again. I am now looking to set up this firewall from a backup instead of…
  • FIREWALL XG210 BATENTENDO 100% CPU!

    Ola, CPU XG210 batendo 100% e parando a operação, na console comando "top" principais processos que estão consumindo são o "garner, snort" alguém poderia me auxiliar com essa situação?
  • Windows Update

    Hello, I am not able to implement the following scenario, all users have to login to the capitative portal to be able to browse the internet. (OK) But I want computers to be able to update themselves Windows Update, Google Crome update, Eset update without…
  • SSL VPN connectivity issues

    Hi All, I've had a Sophos XG Home instance running for a long time with no problems and often use the VPN capability with no problems, I use an iPhone with the OpenVPN app to connect, in the past month or so connecting to VPN has been very hit and miss…
  • high CPU usage on firewall during ATP u2d pattern update

    Hi, is that high CPU load normal on XG430 SFOS 19.5.2? As it is multi cored, I expected only one core exhaused by a update, not the whole system. High CPU on the firewall causes issues with VoIP traffic at least and other applications that rely on…
  • SD-WAN IPSec xfrm routing/failover issues

    Hi, to get used to and evaluate sd-wan and xfrm-tunnel interfaces for seamless site2site vpn-connections, i setup two demo-sfos appliances (using home-license!). Site A WAN 1 to Site B WAN 1 & 2. Everything seems to be correct as i can RDP…
  • Remote Access VPN - IPSEC with Certificate - connection export .scx file invalid - SFOS 19.5

    Remote Access VPN IPSEC with Authentication type certificate does still lead to invalid connection .scx file on SFOS 19.5.0 GA-Build197, SFOS 19.5.1 MR-1-Build278 and SFOS 19.5.2 MR-2-Build624 if the "Organization name" in the Certificate does contain…
  • Sophos XGS 126 HA Link is Down

    Hi We have Sophos XGS126 with firmware SFOS 19.5.2 MR-2-Build62 and every day we have the HA-Interface Link is down. I have checked cable, port but it's correct. Any help or ideas?.
  • Use WAN IP other than firewall for SSL VPN?

    XGS136/SFOS 19.5.2 Is it possible to use an alias WAN IP other than the firewall's IP with the SSL VPN? I'm setting up the XGS to replace an existing production firewall, and using an unused LAN and WAN IP to do it. My plan is that on migration day…
  • SD-WAN on two IPSECVPN

    Good morning, On a XGS126 - SFOS 19.5.2 MR-2-Build624 I am looking to create an SD-WAN policy on two intersite IPSECVPN links The links are configured in "site-to-site" mode I tried to configure a failover group, but I was not convinced by the failover…
  • XG v19.5.2 ipsec VPN routing problems

    I am having difficulty routing across our vpn's. I need for Host1 and Hostt2 to be able to reach Alert11, Alert12, and Alert13 but currently that isn't happening. I can reach Gateway11, Gateway12 and Gateway13. The network looks like this: NetworkA…
  • At my wit's end with WAN bottleneck on FW Home

    My friend decided to run FW Home on my recommendation, but he's having trouble and I took the machine home to troubleshoot. Five days later, I still haven't found the issue. SFVH (SFOS 19.5.2 MR-2-Build624) Lenovo ThinkCentre SFF PC Intel Core i3…
  • Sophos XG 19.5.2 MR2 MTA Mode SMTP Port 25 connection timed out - inbound to internal address

    I have the oddest problem with my XG firewall. Everything works fine, with the exception of the MTA passing mail to the backend server. MTA internal IP is 192.168.128.1 - Mail Internal IP is 192.168.128.12 The problem. Mail is stuck in the mail spool…
  • Sophos Firewall - Web Application Firewall (WAF)

    Hi, I configured the WAF on XGS87 (SFOS 19.5.2 MR-2-Build624), created the protection\authetication policies and applied them on the Firewall Rule. However, when I point the IP address of the published application, the login prompt to enter the username…
  • email scanning failure

    Hi folks, this morning's daily report from the XG was lableed as unscannable, though I wa sable to open and read it without any issues. The email scanning firmware has not been updated for a couple of days,so I at a loss to understand the message…
  • XG 210 IPSEC DOWN FAILED PARSING IKE

    Hi, We are losing our ipsec link after some time. (randomly) Initial connection is ok no problem But in logs we have this message : IPSEC FAILED Couldn't parse IKE message from : X.X.X.X Check the debugs logs ID 18052 If i reinitiate manually…
  • SNAT rule ignored.

    I have the following system: Sophos XG Home SFVH (SFOS 19.5.2 MR-2-Build624) configured in MTA mode. One mail server Some E-mail Account hosted on Cloud Public Server The problem is that SMTP out mail doesn’t engage Nat rule. See imagebelow…
  • New S2S can't connect

    MO: XGS136/SFOS v19,5,2. Not in production yet, setting up to replace production firewall. BO: XG115/SFOS v19.5.2. In production. MO & BO have had an IPSec S2S running for a long time with the MO production firewall. The MO XGS that will replace…
  • Inter-VLAN/Subnet DHCP Relay not working, getting Violation / Local_ACL

    XG210, SFOS 19.5.2 MR-2-Build624 So, I have two VLANs, VLAN 70 - 192.168.70.0/28 and VLAN 100 - 10.0.0.0/24. DHCP server is on VLAN100, I want to relay DHCP requests from VLAN70 to VLAN100 for service. I have a relay set up like so: Name …
  • SFVH (SFOS 19.5.2 MR-2-Build624) New WAF bug throwing Error 404 on authentication

    When making any changes to a WAF rule, form based authentications will stop working and throw an error 404. When editing the affected authentication policy and saving the settings, which reloads WAF, the problem is gone. This can be reproduced on two…