Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • IP group and WAF exception

    Hello Is it possible to use a group of IP addresses in a WAF rule exception? Adding many IP hosts one by one is very cumbersome.
  • WAF - activated Common threat filter kills uploads after 30sec/120MB

    Hi all, I'm having trouble uploading various .iso files (>2.5GB) while "Common Threat Filter" is enabled in WAF. - no error within reverseproxy.log - no problems with a 860MB .tgz file. - different browsers or client devices Some ideas where…
  • Second Webserver

    i have a iis webserver that are publish to the web at the port 80. it reponding to url1.mydomain.com created a webser in XG230 and the nat rules for it. Now i have the need to add a second webserver but this one wil respond to url2.mydomain.com…
  • Is it possible to disable wordpress wp-adin access through WAF?

    Hi all, I am publishing wordpress server with XG. Is there any experience to disable the /wp-admin subpage to internet. It will be enough for us to access that page internally. Thanks for hints Gernot
  • Sophos Firewall - WAF EoL?

    I have noticed, that recently the WAF & E-Mail Features are disappeared in the Firewall Sizing Calculator. So my customer thought to buy a Sophos Firewall, but we are not sure, if the WAF is near EoL, like the E-Mail Module where Sophos forces you…
  • WAF authentication fails

    I have to create a user with username equal to mailadrres ( name@domin.com ) Purpose is to use this user to authenticate with a login form with passthrough in a WAF rule. When i try to authenticate nothing happens, when i authenticate with a username…
  • XG310 Changing rules for Exchange OWA access

    We have an XG310. We are currently migrating our Exchange server from 2013 to 2019. I am trying to figure out how to change our firewall rule for OWA to point to the new server. I go under "Rules and policies", IPv4 and we have a rule created for OWA…
  • Sophos WAF Security Request body (Content-Length) is larger than the configured limit

    Hello everyone I have a Synology NAS behind a Sophos firewall (WAF). On this server is Synology Drive which provides a Cloud Infrastructure. Sadly I cannot upload anything over 1 GB which is problematic. Internally without the WAF it works. The issue…
  • Sophos XG: Problems with WAF and Exchange 2019

    Hello Community, my name is David Lorenz and i have a problem with the WAF from our customer. They use Exchange 2019 on prem. and users from a branch office in egypt have connectionproblems. I already have set some exclusions in the rules because…
  • Is it possible to protect a webserver on Godaddy vps with Sophos Firewall?

    I am new to Sophos firewall, I just deployed a virtual Sophos XG firewall in an Azure virtual machine. Now I want to protect my webserver which is hosted on GoDaddy with the firewall's web server protection, Is it possible and if it is how do i go about…
  • WAF reverse proxy with not working

    Hello, once enebaled the following option reverse proxy does not work anymore. Cookie signing URLHardening tailf /log/reverseproxy.log [Mon Feb 06 22:15:41.552601 2023] [core:warn] [pid 13179:tid 140605555216064] AH00111: Config variable ${URLHardening_HTTP_Hostname…
  • Put Emby container on WAF

    Hello. I want to open Emby for external access. I want to put this on WAF. Emby is run on docker container. I want to be able to access it via https://stream.test.com , can this be done? To be able to use https, will generating a cert for stream.test…
  • WAF: Warning: DocumentRoot [/sdisk/waffiles/########] does not exist

    Sophos FW v19.0.1 (Build 365) - With a Home LIcence Since upgrading to this version, I have had to WAF functionality, and there are no errors being shown in WebAdmin Going into the shell and looking at /logreverseproxy.log I can see the following: …
  • Sophos WAF

    Good day everyone, I am having challenges enabling WAF. The website is using http and on normal dnat its accessible. The moment I create a WAF with HTTPS and disable dnat rules, i get a 403 forbidden error. May you kindly assist. Regards, …
  • Sophos Firewall WAF Policy Crashing System

    Hello Sophos Community Using the latest firmware as of today (SFOS 19.5.0 GA-Build197) on Sophos Firewall, installed as a virtual appliance in Proxmox 7.3-4. It's a home license, on 4 virtual CPUs (host), and 6GB memory. I'm using the official qcow2…
  • Usage of Port 8090 (Captive Portal) for WAF

    Hi, I tried to configure a WAF rule that is using Port 8090, but on save I get the error message, that port 8090 is already in use. This is the Captive Portal Port. Is there any way to change Captive Portal Port or is there any solution to use it…
  • Exchange auto discover

    Hi, i wish you all a happy new year, since we started using XGS2100 appliances with version SFOS 19.0.1 MR-1-Build365, have we noted some problem like Auto discover is blocked. i am trying to call the auto discover service but web application…
  • What is going on with WAF on XG?

    EDIT: Problem solved. You cant limit anyhow Source for specific country without problems on SophosXG - my problem was NAT, if you'll setup NAT then such source will be excluded from any malware scanning, logging etc. We must wait 'till Sophos Team will…
  • WAF documentation missing? or im blind..

    Im trying to find an explanation about metioned topics. But i cant find it in documentatnion, can someone point me where to Sophos is explaing it?
  • WAF Restrict traffic from WAN

    Hello There. Are there any information when SOPHOS will improve WAF option on its iwn devices? Why we dont have such basic option to limit source traffic from WAN only for specific country? So far we can only do IPs..
  • NginX Proxy Manager behind XG

    Hello. Scenerio: [XGHOME]------->[Docker_Revproxy]-----[SynologyNAS] Is it possible to pass origin client IP to reverse proxy? Because Revproxy can see only gateway of Sophos XG. Request on rev proxy look like this: [13/Dec/2022:13:11:20 +0000…
  • Reverse Proxy WebServer behind IPSec Tunnel

    Hello, I have a VPN tunnel to another site, there is a web server that should be reached via a reverse proxy on the XG. The XG has an additional IP address (192.168.0.140) on the LAN interface (the LAN interface has IP 192.168.0.2). The IPSec tunnel…
  • WAF and Logging

    Hello everyone, I have some questions and hope you can help: 1. We are publishing some web servers behind the firewall using WAF. There are some "Forbidden" messages and checking the Reverseproxy.log shows OWASP ModSecurity. As we can see only a simple…
  • Root Certificate automatically included by WAF of Sophos Firewall?

    Hi everyone! We are using a Sophos XGS2300 (SFOS 19.0.1 MR-1). We uploaded a pfx-certificate to the WAF which specifically included only the webserver certificate itself and its intermediate certificate. But, when we check the site with a tool like…
  • WAF - Request Entity Too Large

    Hello, I am running with Sophos XG210 (SFOS 19.0.1 MR-1-Build365) . There is Request Entity Too Large error is still existing when I download file larger than 1 MB from WAF protected website. Here's the error message. ========================…