Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • XGS - Zero Touch Deployment - Completed Zero Touch setup - Bug?

    Guten Morgen, ich habe bei mehreren XGS-Firewalls folgendes Problem festgestellt: Ich bereite die Firewalls über Zero-Touch-Deployment und USB-Stick vor. Nach einiger Zeit meldet sich die Firewall korrekt im Central an, und ich kann unsere Firewall…
  • Microsoft Teams Connectivity Issues Using Sophos as Proxy(XGS 3300 )

    We are experiencing an ongoing connectivity issue with the Microsoft Teams App when conducting online meetings in our organization. Whenever a meeting is scheduled and participants are invited, only the initially invited users can communicate effectively…
  • Sophos XG310 E-Mail: Add ".rdp" files to blocked filetypes

    Hello community, we wanted to add rdp files to the list of blocked e-mail attachements. Under blocked filetypes we added "rdp" but such attachements are not blocked. Other filetypes like f.e. "xls" are blocked correctly. Do we have to add the rdp…
  • STAS issues with RDP

    We use a lot of single user RDP sessions so I've configured STAS with Registry Read polling and it works except for two issues: - When the polling happens every three minutes, the live users for the RDP sessions drop out for up to 10 seconds. - If…
  • SOPHOS XG WAF

    Hallo zusammen, nachdem ich das Problem mit den Zertifkiaten in folgendem Thread gelöst habe, Sophos XG Lets Encrypt Zertifikat stehe ich jetzt vor dem Problem die WAF ein zu richten. Hier mal die Konfig wie es bei mir im Netz aussieht: Router…
  • IPSEC-Tunnel funktioniert nicht seit Umstieg auf XGS

    Hallo zusammen, uns plagen etwaige Probleme seit wir von unserer guten alten Sophos ASG auf Sophos XGS umgeschwenkt sind. wir haben IP-Sec VPN Tunnel kreuz und quer durch ganz Deutschland, IKEv2, Verbindung ist da und es läuft Datentraffic darüber. Probleme…
  • Thumbnail Blocking via Sophos Firewall

    I need to block thumbnail for websites can we do it with Sophos Firewall
  • Block Nudity Images iin searching

    Hello Good Day, I m using Sophos XGS 136 and web policy roles are working well but after a while when I search for sex images they appear but do not open the website. So please how to not appear in searching engine.
  • Permitted network resources issue with SSL VPN

    Hi team , We have configured the SSL VPN in the firewall and allowed a single IP address in the permitted network resources, When we connect with VPN from other network, It will show the entire /24 network IP address as well as a single IP in the…
  • Adding MAC ranges to a MAC list

    Hi, I have a proxmox hypervisor I use it to spin up VMs and LXC containers, and I use MAC addresses to enforce some rules on my Sophos firewall. how can I add a MAC range so all the new VMs that have random generated MAC addresses (under the same vendor…
  • SFOS HA Slave Lizenz

    Hallo zusammen, gibt es in einem degraded Sophs XG HA in dem der Master, die Lizenz hält eine Art Karenzzeit, nach der der Slave die Lizenz "verliert", wenn der Master nicht online ist? Grüße!
  • Sophos XG Lets Encrypt Zertifikat

    Hi zusammen, ich habe Probleme bei dem Hochladen bzw. validieren von den Lets Encrypt Zertifikaten. Die Zertifikate werden vom NGINX ausgestellt bzw. über diesen. Die Zertifikate sind auch gültig und werden auch so im Browser angezeigt. Da ich…
  • trouble with Diagnose

    Hi all, Sophos XGS SFOS 20.0.2 MR2. When I try to check a ping: It only accepts IP Addresses or names without capital letter! I can resolve blabla.domain.local but not BlaBla.domain.local "Please enter a vlid IP or hostname". Is that bug or…
  • Wireless modules on XGS 136

    Good day How do l configure wireless expansion modules on a XGS 136 firewall. Have done all the wireless settings on the firewall
  • PABX and SIP cant ping my sophos in

    I’m currently facing some connectivity challenges with my network setup. My PABX and SIP systems are working fine—they respond to ping requests, so they’re definitely online. However, I can’t seem to get any incoming connections from the PABX to my Sophos…
  • Zero Day Protection - Downloads & Attachments

    Hey guys, I have v21 installed and noticed a few entries under the Zero Day Attachments and Downloads. Some fantastic information in the reports and a bunch of screenshots of the documents / files and a desktop. Question: How is Sophos XGS taking…
  • SSL Remote Access VPN Bridge with directly connected router

    Hello, I have a situation where i need to assign IP addresses to SSL remote access VPN clients from a certain subnet (10.10.10.0/24), and bridge the connection with a router (10.10.10.1) connected to a DMZ interface. I understand that the firewall assigns…
  • rules

    1 Firewall 2024-10-26 14:10:51 Appliance Access Denied N/A 0 PortA1.10 10.10.1.3 10.10.1.255 137 …
  • Alte Sophos XG als WLAN Controller für AP55

    Guten Morgen! Kurze Frage, wir haben vor kurzem unsere XG durch eine XGS ersetzt. So weit so gut. Wir haben noch ein paar AP55, die ja nicht mehr von der XGS unterstutzt werden. Jetzt kam mir die Idee, die alte XG als Basis Firewall und WLAN Controller…
  • Sophos Firewall: SSL VPN - Auto Connect Client On Start-Up Using Provisioning File

    Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents: Overview Configuration Related Information…
  • Sophos Clientless SSL VPN RDP Bockmark

    Hi there, I am looking to configure a RDP Bockmark to allow our user to use the terminal servers on the road without using a VPN. Because of security reasons I want to use NLA, my question woud be is there any way to give the user the ability to change…
  • Firewall issue ping

    I recently add a new firewall for the branch office , so we have 2 firewalls one for the main office and one for the branch office, branch office can ping our ip's, but we from Main branch we can not ping any of their ip's, not even 1, it's really strange…
  • Rant - SSLVPN with Duo RADIUS Proxy Change after SFOS 20.0.0

    So, I wanted to post a bit of a rant here regarding an undocumented change to RADIUS authentication after SFOS 20.0.0 that has broken my DUO MFA implementation. For years I have had my users added from AD and I was able to pull multiple groups through…
  • Problem with URL Filtering

    Hello everyone!! I have a problem accessing a certain GitHub URL. For example, when I try to update Pi-hole the address objects.githubusercontent.com cannot be resolved: At first, I thought it was an issue with Pi-hole itself or with openDNS…
  • Frage Sophos SD-RED20

    Hallo ihr lieben, vielleicht hat jemand einen Rat für mich. Bis her haben wir eine Arzt-Praxis betreut, die eine Nebenbetriebsstätte hatte. Am Hauptstandort ist eine Sophos 107, die Nebenbetriebsstätte hatte eine SD-RED20. Die beiden Praxen teilen sich…