Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Youtube restriction by channel - sort of works

    Hi My kids have to use chromebooks as that is what school issue so I am stuck with Chrome browser. I setup new web category and added keywords for the channels that they can watch without time restriction and another one for domain. I think when…
  • Sophos Firewall - WAF response 403 Forbidden for Internal requests

    Hello Sophos Community, We are migrating from a UTM 9 unit to a new Sophos Firewall unit and I've setup a WAF rule for two internal web servers. When setting up the firewall rule, I chose the Action dropdown option of "Protect with web server protection…
  • Customer having trouble with Quickbooks Payroll Updates after Sophos XGS87 Firewall install

    I have followed the suggestions listed here by adding the URL Pattern Matching exception and HTTPS Decryption and Malware and Content Scanning. QuickBooks Updates failing He is still unable to process payroll. Is there anything new that any of you…
  • Zscaler can conflict sophos firewall web policy

    We have Zscaler & SOPHOS XGS2300 in our network after creating web policy and to on any rule internet getting down
  • Migrating webfilter exceptions from SG to XGS

    Hallo community, I've now migrated a bunch of firewalls from SG to XGS. Usually, I didn't encounter to many problems, but now I might need your help. We have a firewall with a lot of webfilter exceptions (like 1000+ URLs). Is there a better possibility…
  • New to Sophos - Allow traffic to multiple docker containers sub domains

    Hi all, I'm looking for a bit of hand holding and guidance here. What I am trying to do is allow access to internal containers hosting multiple websites and applications. I have a fresh Sophos Setup with no special custom rules or anything yet. I have…
  • Sophos XG SPX Portal not available

    Hello, I have trouble configuring the SPX Portal on our Sophos XG with password specified by recipient. After the email is encyrypted with the outlook addin the link in the mail will lead to the correct host and the corrext port. But nothing happens…
  • Scan to Mailbox packet drop every now and then

    I am using Sophos XGS 2100 Version 20, newly deployed. Everything worked fine however since the deployment Scan to Email would not work properly. The packet is dropped now and then. sometimes it will not go through. I contacted Sophos technical support…
  • Network slow issue and firmware upgrade issue on the XG310

    Dear all, Recently, the network of our office appeared slow phenomenon, when visiting some websites, the speed of loading pictures has obvious slow. we also tried to use the laptop to connect directly to the firewall for testing, bypassing the core…
  • WAF for multiple ports

    Gday Needed to forward 25 ports to a webserver using WAF. I can't for the life of me work out how to enter in more than one port to either. Surely I don't need to create 25 webserver and 25 WAF rules? Anyone done this before?
  • Webfilter Exceptions and Policies

    Hello community, while migrating a Sophos SG to Sophos XGS, I was wondering wheter it is possible to add the defined web exceptions to a web filter policy? So that the exceptions only count for firewall rules with the appropriate web filter policy…
  • Sophos XG 125 dropping Wasabi Cloud Storage despite Exceptions

    Hello, I have 2 XG firewalls running V20 (latest) that are not allowing the connection despite being added directly as exceptions below. s3.wasabisys.com ^([A-Za-z0-9.-]*\.)?wasabisys\.com/ ^([A-Za-z0-9.-]*\.)?s3\.wasabisys\.com/ And s3.us-east-1…
  • Sophos XG Bug: Cannot send Backups using Amazon SES

    Hi Folks, Sophos XG appears to have a bug where it doesn't interact with some SMTP servers properly. In this case Amazon SES (Simple Email Services) cannot be used with Sophos XG for sending Backups. Other notifications work fine but backups generate…
  • Test Policy Web Pages

    Does this website not work anymore with XG? https://sophostest.com/index.html Running a policy test against just the web policy seems to show the correct result... But this test fails, and even classifies the address incorrectly... Going to…
  • XGS WAF Port 80 / 443

    Servus zusammen, leider ärgert mich die Webserver Protection der XGS gerade und ich finde den Fehler Partout nicht. Die Webserver sind soweit passend konfiguriert. Wenn ich die Firewall Regel (Protect with webserver protection) anlege, und dort als…
  • Troubleshoot and Skip Authentication in Direct Proxy Mode

    Hi! We are currently migrating our Sophos UTM to a Sophos XGS (SFOS 20) and have some issues with the direct proxy mode. We have to use this mode because we rely on per-connection authentication for multi-user hosts and content restrictions which…
  • WAF Rules Allowing Unexpected Requests

    Hello, I am getting some unexpected and unwanted requests (trying to find exploits) that are handled by one of the WAF Rules: Here's the WAF Rule that is being it with this traffic: Here's how it looks in the Event Viewer: How can I change the…
  • disneyplus.com - required settings?

    Hello! I´ve issues accessing disneyplus.com with web filtering enabled. The site is working, but when trying to register or login, nothing happens, except a spinning circle. However, allowing the specific client to access anything without web filtering…
  • support.sophos.com is not showing in Web filter Logs

    Anyone else have this issue? community. sophos .com shows up in web filter logs BUT support.sophos.com and www.sophos.com don't. Why is SFOS hiding these logs? I thought it might be some exception but that doesn't seem to be the case.
  • Sophos XGS WAF IPV6

    Hello, We have the problem that users who work from home and only have an IPV6 address cannot use the WAF rules and web server access. Can we allow "any IPV6"? "any IPV4" is allowed. What would be the best approach here? Thank You!
  • Blocked peer to peer and torrents , but still can access pirate bay website

    Good day we have configured Web filtering to block peer to peer and torrents... but we still can access the Pirate bay website.. I have also added a category to block the urls , but we still can access the sites.. we tryed opening on private browser…
  • Firewall ( SFOS 20 ) block url with 502 bad gateway

    Hi there, we want to open the url: https://procurement.cern.ch and get the error: 502 Bad Gateway. If I open the URL without our firewall ( at home...) the website will open ! So the problem is our Firewall with SFOS 20.0.0 GA Build 222. I also…
  • Possible? Webfilter exception for specific filetype on certain website

    Hi there, is it possible to create an exception for a filetype that should be allowed on a specific website only? We have a webpolicy, that restricts filetypes based on file type category. We want to allow one of that types for a certain website.…
  • Disconnect site when quota timed out

    XG SFVH (SFOS 20.0.0 GA-Build222) I have set up a web policy with quota for gaming. I would like it to disconnect user from site after time is used. The way it works now is the user can continue playing as long as they logged in before the quota time…
  • How to Deny Direct IP access from browser ?

    Hi, I need advice how to Deny Direct IP access from browser. So, it only allow access by domain-name. How it done through Sophos Firewall configuration rule? I use Sophos XG 310, SFOS v20.0 Thanks