Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • XG 550 v18.0.1 MR-1-Build396

    Hello Sophos Community, i am experiencing the following problem: I am trying to configure the firewall in a way that it forwards a lot of requests unfiltered to two CMTS devices unfiltered via static routing. The CMTS devices are directly connected…
  • SSL VPN

    SSL VPN issue Hello!! I have actualy a problem, I configured a À SSL VPN. My all setting is perfectly configurate. But when I test in my PC I can't connecte. If I test in my Samsung Note10 + with OpenVPN the connection is successfully but no internet…
  • Route Traffic via VPN IPSec Site to Site for some Specific Website

    Dear i am using 2 Sophos XG 135 - 1 For HO ( Australia ) 1 for BO ( vietnam ) both side connected via VPN IP sec tunel and it working great Follow this KB https://support.sophos.com/support/s/article/KB-000035798?language=en_US i have successfull…
  • OSPF not received on RED client XG

    I am having an issue with one RED tunnel and OSPF. I have a couple of sites with XG devices that I use OSPF for my subnets already, however this one device is not working and I can't figure out why it is not. My XG acting as the RED server shows both…
  • Zone <-> VPN Routing - XG Firewall

    Hi everyone, I recently switched over to XG Firewall from pfSense, thus kindly excuse my insufficient knowledge. For a testing setup I have virtualized XG on ESXi. My plan is to connect using a SSL VPN session to the manage zone, which is the only one…
  • vNet Peering with XG in Azure

    Hi We want to establish a hub and spoke configuration for vNETs in Azure and place our Sophos XG virtual appliance in the Hub vNET. The Hub vNET will then be the default gateway for internet access and a S2S IPSEC to an on-premise Cisco ASA. All "spoke…
  • Wild Card Blocking/Filtering?

    Hi everyone, How and where do I enable wildcard blocking? I want to block all the stupid, ",io" TLD's among others. Something like this; https?://[A-Za-z0-9.-]*\.io/ just not sure where to put it. Thanks in advance!
  • Change request for SFOS 18: Diagnose, Tools, Ping through VTI tunnel

    I was wondering if in one of the next MRs in SFOS 18 it was possible to include one or both of the following changes: Including the VTI interfaces in the pull-down menu options for PING diagnose * When pinging with an internal interface, letting…
  • Access printer+scanner placed in LAN from WiFi

    Hi, I know this topic was discussed several times but I didn't found a solution in the forum yet. I use a XG106 (SFOS 18.0.1 MR-1-Build396) and several AP100c and APX320 access points. LAN has a different IP range than two of the WLANs have. This is…
  • v18 SD-WAN Policy Routing - Wrong Gateway

    Hi All, We have migrated to v18, and I have only just come to try out the SD-WAN policy routing. We have 2 WAN links for internet access: A high speed leased line 500mbps via BT (call it BTNET) and a slower WAN link 50mbps via Virgin Media (call it…
  • Azure peering access across a IPSEC VPN to On-Prem

    I have a VPN tunnel enabled to our Sophos XG in Azure. I then have a resource group peered to that group with the Firewall. I have communication from on-prem to The firewall resource group, and Communication between the resource groups but no matter what…
  • [Fresh From the Press: Latest KB's] Sophos XG Firewall: How to configure BGP

    Hi All, Border Gateway Protocol (BGP) is a path vector protocol that contains path information, enabling the routers to share routing information between autonomous systems (AS) so that loop-free routes can be created. This protocol is generally used…
  • PPPoE DMZ Bridge.

    Hi All. Having a bit of a nightmare getting the XG firewall to operate as my Router/Firewall. I currently have Plusnet as one of my Providers which give me 5 Static IP addresses. Currently, the Cisco RV320 allow me to use one of my IP addresses…
  • XG 330 REV.2 Freezing & Locking up

    Hi everyone! I have been on a hardware rollercoaster with this product. I recently purchased the XG 330 REV.2 last year. Everything was working fine, I made a few firewall rules and have a couple of VLAN's. but nothing too serious. I scoped out the…
  • Is it possible to change the failover method in a link aggregation group?

    I have setup a link aggregation in active-backup mode on two WAN interfaces of my XG firewall. When primary data connection fails the firewall still sees the gateway up and so it doesn't switch up the backup interface. Is there a way to change the default…
  • Routing to another gateway on the same LAN Subnet as Sophos XG

    Hello everyone, I have a behavior I don't know how to solve. Your help will be really appreciated :). My Sophos XG is the default gateway, DGXG (192.168.0.250), for my subnet LAN1. My LAN1 is deployed between 2 sites using a fibre. DGXG is connected…
  • Publish Exchange Server with real IP behind Sophos XG

    hello everyone hope everyone is doing great i have lan network behind sophos with range 10.10.10.0 /24 and i have an Exchange Server in this lan with ip for example 10.10.10.5 and i have a real IP available on my WAN line xx.xx.xx.182 /32 iam…
  • Does XG have a feature that functions like GLBP or VRRP?

    We're looking to implement HA for the LAN and we're wondering if the XG has the ability to do HA without syncing its configurations because each firewall would have different WAN connection settings. Is this available in XG? (I essentially want it to…
  • Routing traffic across 2 subnets and 2 ports but over the same LAN Zone

    I use a Sophos XG Firewall 210 I'm trying to get traffic to flow between my wireless Network and my LAN. This is my configuration.
  • How to set correctly a name for the device (sophos xg) instead of an IP for Captive Portal

    Hi, Good day, i have choosen a device name for my sophos xg firewall (administration>Admin Settings>Host Name: sophos.cedes ) but i can't ping to it, it doesnt work also when i go to https://sophos.cedes:4444 for the admin panel or https://sophos.cedes…
  • Webserver Protection through IPsec VPN

    Hi All, I have a question about routing web traffic through an IPsec VPN. Here's the situation: Site A: Sophos XG with Web Server Protection licensed. Site B: Sophos XG without Web Server Protection and a dumb web server (ventilation unit) which…
  • Integrate Sophos XG transparently with current Juniper SRX

    Hi, I've playing around during the last few days with Sophos XG at home, but I can't seem to make it work the way I want and need. I have a Juniper SRX210 doing all the routing and layer3 filtering, and I want to integrate the XG transparently in…
  • Connect two branch office through head office

    Good afternoon, I have a problem to communicate two remote offices to each other through the head office through SSL VPN. From either of the two remote offices, the services available at the head office and from the central office to any of the two…
  • How can I setup a B2B VPN to access resources that use the same IP address scheme as my network?

    So this one has me stumped and its probably just a lack of knowledge issue. We have three XG firewalls across three geographical locations. We are using a 10. addressing scheme with each location being 10.1.*, 10.2.*, and 10.3.*. Cisco routers are used…
  • Is it possible to set up Full Nat rule for an entire subnet?

    I will try to explain this as best as I can with my limited knowledge in networking. This is using XG 210 hardware. We have setup a connectivity from our Azure VNet to our on premises location with a XG 210. In our Azure VNet we have a subnet (ex. 172…