Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • 8 years plus running no solution to Certificate could not be updated as it is already used by HTTP Based Policy

    When I go to edit the certificate and upload the certificate which is due for renewal ( every 13 months ), it fails with the following error at the top center of the screen: Certificate could not be updated as it is already used by HTTP Based Policy…
  • Certificate wrong after flushing device reports

    Dear Friends: I’ve been following this article because none of my reports were working. Sophos Firewall: No reports show After flushing the reports, it appears as though I never completed the configuration of my WAF certificates. So, I decided…
  • Replacing expired certificate

    Is there a simple way to replace an expired certificate without having to manually replace it with a valid one in all WAF rules and other places where it is used?
  • WAF SSL Certificate Problem

    Dear All, I am facing with a Problem in sophos xg web server Protection, I have created all needed ruls and upload the ssl certificat to xg but in web application rule under the Host server when I select the HTTPS in the dropdaown menu I dont see me…
  • Incorrect WAF SSL Certificate Served To Client

    Hi. I am facing an issue with the Web Application Firewall. I have several WAF rules configured, some using SSL and other are not. They point to a central web server. The domain name is used to differentiate each web app and that is forwarded on to…
  • Web protection

    If I upload a new certificate because it's just been renewed, and then select that certificate in an existing firewall rule for web protection, it automatically deletes all the domains I've associated and puts in the ones it's found in the certificate…
  • WEBSERVER AND WAF

    I have a local web server i would like to publish it so i can access it from outside via port 443 , i've already generated an ssl certificate and i would like to use it via Sophos FW . is it possible to do it via WAF and attach the new SSL certificate…
  • Root Certificate automatically included by WAF of Sophos Firewall?

    Hi everyone! We are using a Sophos XGS2300 (SFOS 19.0.1 MR-1). We uploaded a pfx-certificate to the WAF which specifically included only the webserver certificate itself and its intermediate certificate. But, when we check the site with a tool like…
  • Sophos XG: Cannot change WAF Certificate

    Hi there Last week, my wildcard certificate expired. No biggie. Got a new one, imported it into the firewall, everything ok. When I selected the new certificate in my WAF rules, I was able to save this configuration and expected the firewall to use…
  • Using WAF with servers own certificate?

    It seems that it is impossible to create WAF rules for web servers with https so that the web server would use its own certificate instead of cert from the firewall. Is it really so and is there any trick going around this problem?
  • How to easy update a certificate that is used in WAF?

    Hello, Is there a way to update a certificate that is used in WAF Rules without touching every WAF rule?
  • Updating Cert for the same Cert Domain should not reset the "domains field."

    When updating a Cert from year to year. Why does the "Domains" in a waf rule reset to default. This is annoying. If the coverage of the cert is the same it shouldn't reset the field.
  • Alpha SSL wildcard problem

    Hi! I've bought an Alpha SSL wildcard certificate. I've imported it i my XG 125 But when I go to the WAF firewall rules, I don't see it What stem am I missing? I've done it some years ago, but...I can't remember! Thanks!
  • SSL Cert uploaded to the XG not showing as trusted

    Hi All, I am clearly missing something here, but Google is not my friend on this one as I cannot find out what. I am trying to install an SSL cert to use in WAF and Mail. I created the CSR Downloaded the request Requested the SSL from GoDaddy…
  • WAF & SSL Certificates

    Hello, We have a web server at the back of the Sophos firewall. We recently added a SSL certificate from Godadddy for the domain pointed to the server. The certificate seems to be installed properly in the firewal, however when we are trying to access…
  • Imported certificates not listing in Business Application Rule (BAR)

    I recently performed a factor reset on my XG 85 to resolve an issue with the WAF service causing the BAR firewall rules to hang. Now when I create a new BAR (Exchange General specifically), the certificates that I imported do not appear in the HTTPS Certificate…