Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • RD-gateway connection is interrupted by other WAF rule changes? How and why?

    Hello, I have a question regarding if this a bug, feature or just misconfiguration of our part: I've successfully managed to configure the RD gateway and RD web access in the Sophos XG with WAF rule. I took the RDG 2012 profile provided by the XG and…
  • Using WAF to redirect a webserver root to a specific path?

    Hi all, I use a XGS 2300 with actual path level. We migrated fresh from UTM. In UTM we redirected in WAF to have mail.server.com redirected to mail.server.com/owa (Exchange Outlook Web Access). I only find old articles describing, that this is…
  • Web Server Protection XGS - LAB Test

    Dear All Currently I setup new Lab to test Web Server Protection to have better understanding regarding on how to it works. I trying to provide web server protection for public user to access my internal web server . Below is my network topology…
  • Web Server HTTP Header Information Disclosure

    Hello everyone, I have a question regarding the usage of the command 'set http_proxy add_via_header off' in the CLI. We currently have a website and multiple host services, and we are considering disabling HTTP header information disclosure by request…
  • URL redirection with Sophos XG

    Hi all Am I correct in assuming that URL redirection as it was possible in UTM can no longer be implemented with XG 19.x? We would like to forward Visitors of our Homepage (which is a webserver behind a webserver protection / WAF rule) from ourdomain…
  • Webserver Protection for Host behind IP tunnel

    Hello everybody, I'm currently trying to establish the WAF setup for the current confirguration: Two sites are connected via IP Tunnel and everything is properly working with the static routes set-up. Now we have the need to setup Webserver Protection…
  • Sophos Firewall - Web Application Firewall (WAF)

    Hi, I configured the WAF on XGS87 (SFOS 19.5.2 MR-2-Build624), created the protection\authetication policies and applied them on the Firewall Rule. However, when I point the IP address of the published application, the login prompt to enter the username…
  • SFVH (SFOS 19.5.2 MR-2-Build624) New WAF bug throwing Error 404 on authentication

    When making any changes to a WAF rule, form based authentications will stop working and throw an error 404. When editing the affected authentication policy and saving the settings, which reloads WAF, the problem is gone. This can be reproduced on two…
  • Having issues with WAF rules with 2 web servers - XG v19.5.0

    Hi All, I am trying to have the following setup on my XG unit. sub1.mydomain.com -> internalwebserver1 sub2.mydomain.com -> internalwebserver2 I have created 2 WAF rules on my XG unit, both of them have the FQDN of the public website in the domains…
  • WAF error "ModSecurity: Request body no files data...."

    Hello, Im hosting for myself some things. One of it is PingVin-Share which is behind WAF on XG. I was trying to upload a file abut 10mb... But im getting an error. So i went to console -> advanced shell logs are below: [Sun May 14 20:00:11.856339…
  • WAF for Web-Server behind IPsec-Connection

    Hello, I have the problem with an XGS 107 (19.5.2-B624) that a web server (10.203.111.101), which is located behind an IPsec connection, is not reachable via the WAF. When accessing the web server via the Internet, I get the code 503. However, the problem…
  • Web protection

    If I upload a new certificate because it's just been renewed, and then select that certificate in an existing firewall rule for web protection, it automatically deletes all the domains I've associated and puts in the ones it's found in the certificate…
  • WEBSERVER AND WAF

    I have a local web server i would like to publish it so i can access it from outside via port 443 , i've already generated an ssl certificate and i would like to use it via Sophos FW . is it possible to do it via WAF and attach the new SSL certificate…
  • protect internal webserver

    hello i have 2 different webservers running in my internal network how should i protect them in my sophos from external attacks ? thank you
  • Web Server Protection XGS

    Dear All I currently setup new lab to test Web Server Protection at XGS firewall. My setup: 1. Web Server using Xampp (LAN Zone) - IP: 192.168.100.2 2. Virtual Firewall XGS. (LAN Interface IP: 192.168.100.254) ( WAN Interface IP: 192.168.43…
  • Fail2ban hinter XGS WAF

    Hallo zusammen, wir wollen unsere Webserver mit Fail2ban umstellen, sodass diese über WAF erreichbar sind. Da dann im Log des Webservers die Interne IP der Firewall auftaucht, wird leider diese von Fail2ban gebannt. Man kann zwar die IP X-Forwarded…
  • Emby/ Plex behind WAF HTTPS slower performance?

    I am trying to host Emby server behind WAF with HTTPS configured. I am able to access the server successfully, but when it comes to playback, it doesn't want to start playing. It will seem like it's buffering, with an image of loading, but never starts…
  • RDWeb per WAF

    Hey there, I´m trying to publish a RD Web Gateway with a Sophos XG and WAF. Configured anything like described here . Login and the RD Web Overview works, but not the Conenction to the RDS. For testing I habe disabled the entire protection section…
  • Cloudflared WAF & port showing open

    Hello everyone, Me and also a friend have the same issue with a waf rule. We both have a cloudflare proxied domain name (lets say system.somedns.com) that points to our wan IP. Since it's cloudflare proxied, the ip of the domain name points to cloudflare…
  • Sophos E-Mail on XG with SFOS 19.5.1 MR1 blocking attachments bigger than 1MB

    Hi community, we've experienced again the problem that sending e-mails with attachements bigger than 1MB are blocked by WAF. We had this problem about two years ago and already set the limits via advanced shell. We did the same thing as described in…
  • XG Reverse Proxy fails

    Hello experts I am struggling to get a Docker container of vaultwarden up and running in my internal network. Since vaultwarden has limited support for HTTPS, I tried to use XG as reverse proxy, but I cannot connect. I assume, it is irrelevant for the…
  • IP group and WAF exception

    Hello Is it possible to use a group of IP addresses in a WAF rule exception? Adding many IP hosts one by one is very cumbersome.
  • WAF - activated Common threat filter kills uploads after 30sec/120MB

    Hi all, I'm having trouble uploading various .iso files (>2.5GB) while "Common Threat Filter" is enabled in WAF. - no error within reverseproxy.log - no problems with a 860MB .tgz file. - different browsers or client devices Some ideas where…
  • How to share port TCP 443 for WAF and SSL VPN?

    Hi everyone, I see a lot comments at this forum where I can see, that sharing Port 443 TCP for WAF and SSL VPN is working. The documentation says, that it is not possible: https://docs.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp…
  • Second Webserver

    i have a iis webserver that are publish to the web at the port 80. it reponding to url1.mydomain.com created a webser in XG230 and the nat rules for it. Now i have the need to add a second webserver but this one wil respond to url2.mydomain.com…