Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Poor Spamfilter v20MR2

    Hi everybody, we have installed a Sophos v20 MR2. However, we had to realize that the spam filtering is very poor compared to the UTM. The Sophos is acting as an MX and works in MTA mode. Spam protection is active as a policy and basically has all options…
  • Possible to Backup/Restore to a different (higher/lower) model?

    Hi, i was just wondering if it's possible with the latest SFOS to backup and restore from a XG 210 to a XGS 2300 and from a XG 230 to a XGS 2100? Thnaks alot!
  • IPSEC site to site VPN, initiator behind router

    We are wanting to connect our remote office, which is in a managed/shared office space building, to our head office. We have no control over the shared office netowrk. We have a XGS in the managed office space. The internet connection is supplied…
  • Webserver mit mehreren Domains

    Guten Abend, wir möchten gerne mehrere Web-Applikationen auf unserem Server über das Internet bereitstellen. Hierzu habe ich bereits beim Provider die entsprechende Subdomain auf unsere öffentliche IP geleitet. Daraufhin habe ich in der Sophos via…
  • XGS2100 (SFOS 20.0.2 MR-2-Build378) - Fritzbox 7490 VPN

    Hi, after updating to 20.0.2 the Site to Site VPN connection between our XGS (Host) and the Fritzbox is not working anymore. Before the Update is was workking without any problems. A downgrade to 20.0.0 is also impossible as the XGS always tells Firmware…
  • HA_degraded, device is showing faulty

    Hi, We have configured a HA in the site and it was working fine from last one year, HA degraded yesterday, Primary device is showing faulty All the cable connections are working fine, How to resolve this issue ? What would be the reason for…
  • SD-RED Firmware 3.0.010 pattern update released

    We have just launched version 3.0.010 of the SD-RED firmware pattern update. You can download and install the firmware right away. This is a maintenance release that features essential security updates. The update includes improvements to multiple RED…
  • Sophos Reports showing IP rather than websites visited by users

    Hi Community... Please assist - Customer has a sophos 125 XG SFOS 20.0.2 running web filter and support license only- Web filtering works fine - Customer requested a report on a specific user on websites visited/ internet usage - Reports show IP address…
  • old Queued mail found within Mail-Spool

    hello, I have a really old queued mail found within mail spool. in this case the email is not (was not) important, but how can that happen? In the meantime, many new emails have been delivered from the same sender to the same recipient. I'm asking because…
  • IPSEC VPN Routing traffic between multiples sites

    Hi, We need to establish a multiple site to site IPSEC VPN with a XG86w as the HQ. Both remote sites have a TELTONIKA RUT240 router. I am able to ping from HQ both remote sites, and from each remote site the HQ, but can’t ping a remote site from…
  • Display the real IP in Web Application Firewall (WAF) when using Cloudflare

    Many of us are using Cloudflare or similar services to protected their Extranet / Webmail and other public websites using the Sophos WAF. It's possible to display the real IP addresses on any Linux servers behind the firewall by enabling Pass host header…
  • TLS on syslog

    Hi, we have a problem with transferring syslog from Sophos firewall to the Arcsight SmartConnector. When we try UDP, logs can be seen in connector. However, with TLS communication fails. This is only example, but ours handshake also fails at Change…
  • Sophos XGS SSL VPN

    Hello, We are currently using an XGS firewall and would like to give users access to internal resources via SSL VPN. Several SSL VPN policies are available for this purpose. The users are in different groups and these are assigned to different SSL VPN…
  • Configured WAN lP in Sophos XGS136, link is up but internet is not working

    Hi Configured one more WAN IP in the Sophos XGS136, link is up but traffic is not moving through new link, checked load balancing, everything is looking fine Pervious link is working fine, however the new link is not working, able to ping 8.8.8…
  • XGS mit einer Schnittstelle - also parallel zu einem anderen Router

    Hallo, ich versuche gerade vergeblich, eine XGS neben einer anderen Firewall zu betreiben. Die XGS soll im ersten Schritt mit nur einem Port als vorgeschaltetes Gateway und WebProxy dienen, bis das Netzwerk komplett umgestellt ist. [PC] -> [XGS…
  • Comcast Gateway Modem with Built In Wireless Model CBR2_t

    Hello World. I have a question that I already believe I know the answer to but I figured I'd ask anyway. I have Comcast Gateway that has its own wireless built in of course. I want to firewall the wireless connectivity behind my Sophos firewall. Is…
  • IPSEC Site to site conneted

    I Need help regarding my ipsec. I have two sites HQ and remote site. The firewall is connected through ipsec. I have set both inbound and outboud rules. But am still not able to ping each end of the firewall or to remotely access resources at HQ. Kindly…
  • Sophos XG resolves external Domains even no external DNS server is configured

    Hey Guys, I am using the Sophos XG as DHCP server which provides two DNS servers. One is a Pihole and the other one is the SophosXG itself. So normally the devices should resolve internal and external domains via Pihole, but when it is not available…
  • I cannot connect to VPN using strongswan or ovpn on linux

    My server is Sophos Firewall XG125 (SFOS 17.5.16 MR-16-Build830). Sophos connect works perfectly but the .ovpn file downloaded(via user interface) will not connect. I also used the details from the .tgb to build a config file for strongswan, but didn…
  • Unable to use "Reject based on RBL" in SMTP Policies

    Affected Version: SFOS 20.0.2 MR-2-Build378 When creating a new SMTP route & scan policy in Protect > E-Mail > Policies & exceptions you are unable to enable "Reject based on RBL". When you already have an existing SMTP Route & scan policy with "Reject…
  • IPsec Remote Access from iOS using certificates not asking for password

    Hi guys I can't see the wood for the trees -- so please forgive me this (probably stupid) question: When using PSK for IPsec without certificates, everything is working properly. It asks for password (or I save my password) click Connect and it works…
  • Email deliver problem on Sophos XG v20 MR2 - Hosts have been failing for a long time.....

    This is more of a "Help the next guy out" post. So, I was thinking that my email was unusually quiet for the past couple of days, so I finally got around to checking things out, and discovered that I hadn't received any email for 3 days!!!. Did the…
  • NS300 Not Reachable from Sophos XG4500, but Can Call Outside

    Hi everyone! I’m facing a puzzling connectivity issue in my PABX setup. My NS300 cannot be pinged from my Sophos XG4500 when my SIP router is connected to the core switch. However, I can still make calls outside, which adds to the confusion. Coreswitch…
  • Block or report on PPTP centrally

    I have 200+ firewalls that have been out there for quite a well and I've found a few which still have PPTP enabled from a different era. Staggering. For some reason, PPTP isn't in Central Partner firewall templates so can't disable there. Can't disable…
  • WAN latency increases towards VPN branch offices

    Hi, not a huge problem, but I cannot find logic behind. I have XGS-136 in main office, and from there I monitor with PRTG 2 distant branch offices, which both have XGS-87. Interesting, that both branch offices experience increase in PING latency at…