Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • SFOS 19.5.3 MR-3: Web Server Protected, Path-Specific routing - should this config work?

    Hi, I have a WAF rule configured for path-specific routing, however, the routes I am specifying are all to the same target web server, but with different restrictions. e.g. / - restricted to specific IP ranges, target sevrer1 /myapp/ - not restricted…
  • Order of domains in WAF rules

    XGS Firewall, WAF rules has 10 listed domains. What is the sort order based on for these domains? Whenever we delete one from say position 5, add a few new ones, then add the number 5 one again (we have saved and reopened the rule multiple times)…
  • is it possible to combine SFOS WAF with the built in OTP / MFA function

    I found some old posts (>2y ago) about the XG WAF module not supporting MFA authentication for a webservice. Has this changed since? We want to use MFA before using on-prem Exchange OWA. Many internal users already have an Sophos MFA token and it…
  • WAF rules and IIS redirects with trailing slashes

    Situation. We have a WAF rule with several test sites in the domains list. Example below. test1.testurl.com test2.testurl.com test3.testurl.com test4.testurl.com These all point to one IIS. On the IIS these are all separate sites. When we…
  • Incorrect WAF SSL Certificate Served To Client

    Hi. I am facing an issue with the Web Application Firewall. I have several WAF rules configured, some using SSL and other are not. They point to a central web server. The domain name is used to differentiate each web app and that is forwarded on to…
  • WAF and RDG 2019

    Hi all, SFOS 19.5 Just got a problem with WAF and RDG 2019, i can't log to my server and i have this error: /rpc/rpcproxy.dll WAF Anomaly Inbound Anomaly Score Exceeded (Total Score: 13) Hope i will find…
  • WAF Authentication Forms shows 404 after upgrade to SFOS 19.5.3 MR-3-Build652

    After upgrade - all WAF with authentication form with template shows 404. Opening and saving Protection Policy - does not solve the issue. Recreation of Authentication Policy - does not solve the issue. Reimporting form template - does not solve…
  • How to config waf without domain

    I want to set up a WAF on the firewall, but a domain needs to be set in the WAF rules. My server does not have a corresponding domain, how should I set it? I checked the official website manual, but I don't quite understand the statement in the manual…
  • XGS webserver protection on port 8080

    Hi y'all, I am struggling with the following scenario: Webserver protection works fine for several sites. Now I would like to protect an internal web service that should be available via https (yes, http S ) on port 8080 (I know...). Webserver Protection…
  • Confused rule id and broken WAF rule.

    Hi, I'm having trouble with the WAF, XGS 2300 v19.5.1 I add the webserver web .xxx.xxx - it has policy ID 129 . But if I go to web .xxx.xxx in the log it shows that web.xxx.xxx has policy ID 43 . I get a 503 error But the policy ID 43 is spsluzba.xxx…
  • RD-gateway connection is interrupted by other WAF rule changes? How and why?

    Hello, I have a question regarding if this a bug, feature or just misconfiguration of our part: I've successfully managed to configure the RD gateway and RD web access in the Sophos XG with WAF rule. I took the RDG 2012 profile provided by the XG and…
  • Using WAF to redirect a webserver root to a specific path?

    Hi all, I use a XGS 2300 with actual path level. We migrated fresh from UTM. In UTM we redirected in WAF to have mail.server.com redirected to mail.server.com/owa (Exchange Outlook Web Access). I only find old articles describing, that this is…
  • Web Server Protection XGS - LAB Test

    Dear All Currently I setup new Lab to test Web Server Protection to have better understanding regarding on how to it works. I trying to provide web server protection for public user to access my internal web server . Below is my network topology…
  • Web Server HTTP Header Information Disclosure

    Hello everyone, I have a question regarding the usage of the command 'set http_proxy add_via_header off' in the CLI. We currently have a website and multiple host services, and we are considering disabling HTTP header information disclosure by request…
  • URL redirection with Sophos XG

    Hi all Am I correct in assuming that URL redirection as it was possible in UTM can no longer be implemented with XG 19.x? We would like to forward Visitors of our Homepage (which is a webserver behind a webserver protection / WAF rule) from ourdomain…
  • Webserver Protection for Host behind IP tunnel

    Hello everybody, I'm currently trying to establish the WAF setup for the current confirguration: Two sites are connected via IP Tunnel and everything is properly working with the static routes set-up. Now we have the need to setup Webserver Protection…
  • Sophos Firewall - Web Application Firewall (WAF)

    Hi, I configured the WAF on XGS87 (SFOS 19.5.2 MR-2-Build624), created the protection\authetication policies and applied them on the Firewall Rule. However, when I point the IP address of the published application, the login prompt to enter the username…
  • SFVH (SFOS 19.5.2 MR-2-Build624) New WAF bug throwing Error 404 on authentication

    When making any changes to a WAF rule, form based authentications will stop working and throw an error 404. When editing the affected authentication policy and saving the settings, which reloads WAF, the problem is gone. This can be reproduced on two…
  • Having issues with WAF rules with 2 web servers - XG v19.5.0

    Hi All, I am trying to have the following setup on my XG unit. sub1.mydomain.com -> internalwebserver1 sub2.mydomain.com -> internalwebserver2 I have created 2 WAF rules on my XG unit, both of them have the FQDN of the public website in the domains…
  • WAF error "ModSecurity: Request body no files data...."

    Hello, Im hosting for myself some things. One of it is PingVin-Share which is behind WAF on XG. I was trying to upload a file abut 10mb... But im getting an error. So i went to console -> advanced shell logs are below: [Sun May 14 20:00:11.856339…
  • WAF for Web-Server behind IPsec-Connection

    Hello, I have the problem with an XGS 107 (19.5.2-B624) that a web server (10.203.111.101), which is located behind an IPsec connection, is not reachable via the WAF. When accessing the web server via the Internet, I get the code 503. However, the problem…
  • Web protection

    If I upload a new certificate because it's just been renewed, and then select that certificate in an existing firewall rule for web protection, it automatically deletes all the domains I've associated and puts in the ones it's found in the certificate…
  • WEBSERVER AND WAF

    I have a local web server i would like to publish it so i can access it from outside via port 443 , i've already generated an ssl certificate and i would like to use it via Sophos FW . is it possible to do it via WAF and attach the new SSL certificate…
  • protect internal webserver

    hello i have 2 different webservers running in my internal network how should i protect them in my sophos from external attacks ? thank you
  • Web Server Protection XGS

    Dear All I currently setup new lab to test Web Server Protection at XGS firewall. My setup: 1. Web Server using Xampp (LAN Zone) - IP: 192.168.100.2 2. Virtual Firewall XGS. (LAN Interface IP: 192.168.100.254) ( WAN Interface IP: 192.168.43…