Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Blocking Ads best practice (bulk updates to URL Groups?)

    We use mostly Apple equipment (MacBook, iPhone, iPad) and on our MacBooks we have Little Snitch which is an application-aware outgoing firewall that kills attempts to reach out to advertising sites, trackers, etc. This doesn't help the phones and tablets…
  • keyword block in URL not working

    Hi , I am on Sophos XG 18.5. URL to block: www.google.com/.../ads.js I have added a custom blocking category with keyword filters like below www.google.com/adsense/search/ads.js search/ads.js adsense/search/ads.js but this does not block…
  • Duplicate Wed Exceptions

    XGS4500 (SFOS 18.5.3 MR-3-Build408) Since new this device has duplicate Exceptions (example below), there are 5 of them. There is what looks like a factory one (no delete option) and a second one with 'Original' After the name. I cannot delete the one…
  • Websites blocked for User PC's but not Server?

    I have a client where the user's logged into their pc's cannot access certain categories of websites. If i sign on to their server with our admin account we can view all the websites no issues. We have an XG450 installed on site. We even turned off all…
  • When I try to download Unreal Engine 5 through Epic Games it gets frozen at 21%

    Whenever I try to download Unreal Engine 5 through the Epic Games launcher it gets stuck at 21% saying there is a network error. I am currently on Epic Games support but I'm 90% sure this is something with our firewall. Any help would be greatly appreciated…
  • Categories - External URL Database Sync

    Hi. Regarding Sophos XG, under menu Protect --> Web ---> Categories I have created an external URL database to keep a centralized Black List of domains. it works fine but it seems that it only refreshes the contents of the .txt file every 24/48…
  • Transparent proxy timeouts, direct proxy not

    Transparent mode results in random timeouts. We tried various things trying to find the issue while running in transparent mode, then recently discovered the issue goes away in proxy mode. Not sure if this is a common or known problem with a fix?
  • Restrict login domains for MS365

    One method of tenant control in SaaS is to insert information on permitted domains into HTTP headers by proxies on the path. In Sophos XGS, the "Restrict login domains for Google Apps" setting in the Web Policy is considered to be applicable to this…
  • Whatsapp

    Hi, I can't use whatsapp web in my organization. After recognize with qr code, it show "messages completing " without show the correct window (message list). I inserted all exception in url policy, without success.
  • Sophos XG Firewall Web Filter

    Hi. We have a number of new Sophos XG Firewalls and we are experiencing issues with the Web Filtering aspect as in, it just will not work. Here is an example of a setup at one of our sites. At this site the below has been configured to allow a residents…
  • How to block tiktok app

    Hey Guys, Is there anyway to block TIk tok ? I see there is no Sophos App for this .
  • Customise "Use x minutes of my quota time now"

    Hello guys I successfully implemented a time quota in a specific category for my kids. If I go to Web --> User notifications, I see that I can customize the messages for the block pages. I did it , but I see no way to customize "Use x minutes of…
  • Block sites

    I have 2 offices at different locations at both offices there are sophos. Now i want to block some sites at both offices but it only works on head office. Please help me
  • Apple updates

    Hello, I have some users on my LAN trying to update their MacBooks pro (everyone with the HTTPS decrypt enabled), but they are having troubles. Can someone tell which https decryption exception should I add, so they can update their MacBooks? And…
  • policy override

    I have blocked facebook using web category (social networking). i enable override and created the user and group to override the website....outcome, when i insert the code from my user portal the site is not opening....shows its procesing then blocked…
  • Safe Search Ver - SFOS 18.5.2 MR-2-Build380

    Hi, I just Recently Update my SOPHOS XG 430 Firmware Version From Ver 17.5 to version 18.5.2 MR-2-Build380 and i found that Safe Serch are not Working can one idea About this this is a BUG Note : in Version 17.5 it is Working OK without any Problem…
  • Youtube block for a specific time period

    Hi, I want to enable Youtube for a specific time period and needs to block for rest of the time. I have created a rule with time specific but it doesnt work. Can u help me out on this.
  • Hide web policy override access code while typing

    Hi, I'm new to XG firewalls, so please bear with me. I have created a user and a web policy override access code as outlined here: https://support.sophos.com/support/s/article/KB-000038467?language=en_US This is working as expected, but when typing…
  • Allow Internet through MAC , Use Sophos as Proxy

    Hi, Community, one of the problems we are facing is to allow the internet based on MAC address to both the VLAN Users if this is not possible due to the involvement of the router then is it possible to create a rule on FW to use it as a proxy. My network…
  • Upstream proxy

    I am currently migrating a customer from utm to xg. He is using an upstream proxy for any some corp websites, the others are going directly on Internet. All the clients are using the utm as a explicit proxy at this time. As there is a default…
  • apple.com URL Filtering Exception

    We have a URL Filtering Exception for all apple.com traffic. See below. ^([A-Za-z0-9.-]*\.)?apple\.com\.?/ Is it possible to craft/recreate the above to apply the exception to all apple.com traffic except music.apple.com ? Therefore blocking music…
  • Changing web filtering solution

    Hi there, we are a school that currently has a Sophos XG that is doing our web filtering. We now want to change to Smoothwall for the filtering and would like some advice please. Currently, the setup is: LAN > XG > Router > WWW With the Smoothwall…
  • HTTPS Decrypt and Scan Encountering Warning Pages

    Hey Sophos, We've recently been testing Packet Inspection / HTTPS Decryption and was mostly a success, but some sites were presenting the below, even when we had the appliance cert installed. Can someone shed some light as to what was causing this…
  • Omitting an exception for a specific group

    Hello, Once that a policy checks exception has been created, can I ignore this same exception for a specific group by a firewall rule (it can be by a IP Range, IP list, networks, Host Group, by selecting an entire in interface... it doesnt 'matter)…
  • Content filter battle against images containing text

    Hey folks, So I don't think there is an answer for this yet unless there is some funky AI based technology that might be in the endpoint soon. A school came to me saying there were inappropriate images being displayed. Turns out there wasn't at all…