Sophos Firewall: v21.0 EAP1: Feedback and experiences (EAP Thread)

Release Post:  Sophos Firewall v21 Early Access Announcement 

Whats New Link: https://assets.sophos.com/X24WTUEQ/at/7t8k46h9ttmxt6pn8g58k7wb/sophos-firewall-key-new-features-v21.pdf 

Please provide feedback using the option at the top of every screen in your Sophos Firewall as shown below or via the Community Forums.

NOTE: Sophos Firewall v21 does NOT include support for XG and SG Series appliances. XG Series EOL is March 31, 2025.
XG/SG Hardware will find them self until the EOL on the V20.0 Branche with MR2 + 
Sophos SFOS Home users are not affected, as SFOS Home is running the software version. 

For LE Related config issues, please review this post first:  Let´s Encrypt Deep Dive & Debugging in SFOSv21.0  



LE
[bearbeitet von: LuCar Toni um 8:59 AM (GMT -7) am 31 Aug 2024]
Parents
  • I imported a fairly trim, reputable URL list (from URLhaus) and it worked well and takes only about 8% of allocated memory, on a low-end XGS87. I'm curious if this will block anything, since Sophos' X-ops feed seems to cover most bases. So more of a curiosity at this point, but appreciated and we'll see how it goes.

  • Hi  ,

    The firewall first implements MDR threat feeds followed by Sophos X-Ops and Third-party threat feeds.

    If an Indicator of Compromise (IoC) exists in Sophos X-Ops and Third Party Feeds, and Sophos X-Ops is set to Log and drop, the firewall drops the traffic, logs the event under X-Ops, and doesn't check further—no event for Third-Party feeds.

    If the Action is set to Log only or Monitor, the firewall logs separate events for Sophos X-Ops, and Third-party threat feeds.

    Thank you!

Reply
  • Hi  ,

    The firewall first implements MDR threat feeds followed by Sophos X-Ops and Third-party threat feeds.

    If an Indicator of Compromise (IoC) exists in Sophos X-Ops and Third Party Feeds, and Sophos X-Ops is set to Log and drop, the firewall drops the traffic, logs the event under X-Ops, and doesn't check further—no event for Third-Party feeds.

    If the Action is set to Log only or Monitor, the firewall logs separate events for Sophos X-Ops, and Third-party threat feeds.

    Thank you!

Children
No Data