Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • How to fix error: "Following domain(s) will not be covered by selected HTTPS certificate."

    I am trying to get my ActiveSync setup to work across my Sophos XG 18.5.3 MR-3 install. I follow the recipe found at https://support.sophos.com/support/s/article/KB-000040209?language=en_US When I try to save the firewall rule mentioned towards the…
  • Websocket request not passing through WAF HTTPS traffic

    We have a web server that sends websocket requests when being accessed. We are able to make it work through HTTP traffic, but when we got an SSL certificate to make it HTTPS, the websocket requests fails. I have tried using Path-Specific Routing to…
  • WAF Rewrite HTML option disables javascript

    Hello guys. I am using waf and I noticed that when Rewrite HTML is checked javascript is not loading. For example I have a phpsysinfo script running. When I access it, while it is supposed to use bootstrap to display the page, it redirects me to the…
  • Webserver protection with "nocanon" option required for matrix-synapse

    Dear Sophos, I am operating a matrix.org synapse backend, and for federation to work properly it is important that the apache virtual host is configured with the "nocanon" option. My assumption: Normally, mod_proxy will canonicalise ProxyPassed URLs…
  • Toggle web server in WAF rule via API

    Hello, I am trying to set up kind of a "blue-green" deployment environment for our website. We already have a working web server and a firewall (WAF) rule pointing to this web server. I've added a second "web server" and I now see it in the list under…
  • publish two web server app using two IP publique

    I have two public IP addresses behind a sophos XG, I need to publish two web servers in the DMZ zone. I created the publishing rules for both servers. only access to web server 1 is allowed from IP1 address. access to web server 2 from IP2 address is…
  • Too many logs in WAF

    Hello eveyrone, I have created a WAF rule on all my Website, which is in "moitor" mode : I went to reverseproxy.log to see if I had errors, warning... and I have many many logs like : [cookie:error] [form_hardening:error] [security2:error…
  • Block specify IP to a specify path WAF

    Hello, I would like to do this : Allow all internet v4 IP on www.mywebsite.fr Allow specify IP on www.mywebsite.fr/admin Is it possible with Sophos XG 18 ? Thank you very much.
  • Using WAF with servers own certificate?

    It seems that it is impossible to create WAF rules for web servers with https so that the web server would use its own certificate instead of cert from the firewall. Is it really so and is there any trick going around this problem?
  • Web Server with HTTPS encryption showing different responses from both internal and external network

    We have a new SSL certificate installed in Sophos for a website we are hosting. When I configure the web server with an HTTP encryption, there is no issue. But when I change it to HTTPS encryption, these are the issues we are having: From internal network…
  • Bad request

    Hello! We are using sophos Web Server Protection to proxy our websites, One of our editors is suffering from this error: Sometimes get this message after 2 mins of usage, sometimes 15-30 mins, after this tried to flush all caches (10x times a day!)…
  • Size of a request header

    We have XGS3100 and in one web application, the following error is displayed in the browser when passing credentials: Bad Request Your browser sent a request that this server could not understand. Size of a request header field exceeds server limit…
  • WAF: No web server configured

    I have a fresh install of Sophos XG Firewall Home (SFOS 18.5.2 MR-2-Build380) Everything is working except I can not get the WAF to recognize that I have created as web server. I created a host in Host and Services ! created a web Server in Web…
  • Webserver with public IP not accessible

    Hi, I have one problem with my webserver. It´s an VM, with only a public IP, so no internal private IP, that it can be translated to. I set up firewall XG from ground, since I was expecting problems with one VLAN, that wasn´t accessable anymore, even…
  • WAF configuration really working for recent Exchange(2016/2019)/RD Gateway (2016/2019/2022)

    Hello, Does the Sophos XG/XGS WAF (18.5) really work with recent Exchange and RD Gateway (2016/2019/2022) ? I have searched in community, in manuals, all over the internet, but I didn't find any "clear" answer, article or procedure with a WAF configuration…
  • WAF Issue. Error during SSL handshake

    hi, i am configuring WAF , so that server which is behind the firewall woudl be access over interner securely. i configured WAF, getting following error Proxy Error The proxy server could not handle the request. Reason: Error during SSL handshake…
  • WAF with radius authentication and Duo proxy problem

    Hi all, I have the exact problem as described by this member below. Basically, I have the radius and duo authentication proxy working fine for the user portal and SSL VPN but it won't work with WAF. The WAF authentication form seems to send multiple…
  • Domestic HTTP Traffic Redirect to HTTPS

    Hello all I need to reidrect all external HTTP traffic into HTTPS traffic before it reaches the clients. this need to be done without the need of any action needed from the clients side. is this feasible ? and do we need to purchase an SSL certificate…
  • WAF log after pentestig

    Hello, We did a Pentesting for 5 days on your Website which are behind XG WAF Firewall. In the firewall rule, Advanced, Protection, We create a protection policy with is in Monitor Mode So now I would like to see if we have log of the Pentesting…
  • WAF & Portal via 443

    Hi, how to define a WAF rule to reach the portal via port 443? Portal is reachable via port 4443, but the WAF rule seams not to work. We use SNI to direct the WAF rules to the right server. Works that way on UTM, what did I wrong? Thanks Henri…
  • Reverse authentication

    Hello, I would like for SOFS 18 to authenticate users on the device before granting access to a web server using WAF. I found the article below but refers to UTM 9 and I can't adapt to SOFS 18. Can anyone help please? Thanks support.sophos.com…
  • Pass a WebSocket connection through WAF

    Hello Community, for one Web-Service we need to pass a WebSocket through the WAF. Is it possible to create a rule for " wss://" Traffic? Thanks, Ben
  • Sophos Firewall: WAF cipher suites - How-To activate change

    I've followed KB-000041605 and the Posting from KingChris and changed the entry in the file /usr/apache/conf/httpd.conf After that I've restarted the WAF service. Still there has been no change in the reported Active Cypher Suites on the SSL LABS…
  • WAF: TLS/SSL Server uses only Default Prime Numbers

    At a Pen Test for one of our websites behind WAF we received the message that the server was using only Default Prime Numbers. How can we change this?
  • BigBlueButton Sophos XG 18

    Hey Fam, dows anyone ever worked with Webserver protection and bigbluebutton? I´ve created a new webserver (https) and called everything that comes to bbb.domain.com go to my internal bbb server. So far so good, I can login, I can browse BUT when…