Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Traffic won't go through policy based S2S IPSec tunnel

    Hi guys, I'm trying to setup a policy based site-to-site tunnel, but the traffic won't go through the tunnel. Like the tunnel itself is up and running. Per the others party policy, we had to use SNAT and the needed subnet is not private: 100.270.xx…
  • WinSCP can't access log folder

    Any ideas, using WinSCP to access my XG 19.0.1 firewall on my LAN. Can authenticate fine with admin. Can browse and transfer most files. However, /log/ or /var/tslog/ give me "Error 2 - permission denied." If I copy log files from /log to another folder…
  • image

    Hello everyone, I am just getting started with sophos firewalls and i could use some advice. I got an old sg210 from work hoping to play around with it and design my own lab at home. i would like to install an xg image on it. tried with an usb the…
  • ApplianceCertificate incorrect object

    Hi as per the subject in the ApplianceCertificate certificate in the subject field I have incorrect values such as the email field, in which na@example.com is reported how can I correct this data? thank you Oggetto /C=NA/ST=NA/L=NA/O=NA/OU…
  • Sophos AP100C Access Points issues

    Hi Team We are using Sophos AP100C Access Points in our office We are facing the below issues - Google Meetings are getting dropped ( you lost your network connection. Trying to Reconnect ) - Getting Pocket loss - Wi-Fi disconnection Sophos…
  • IPSec connection not used

    Hi all, i have a ipsec-connectin, but packets didn't use these: XGS2100_RL01_SFOS 19.0.1 MR-1-Build365# ip route show table 220 192.168.192.1 dev ipsec0 scope link src 192.168.179.254 XGS2100_RL01_SFOS 19.0.1 MR-1-Build365# ip route show table all…
  • Sophos XGS SSL-VPN .ovpn file

    Some trouble with .ovpn file for linux or android. After we add a SD-RED device, there is missing one "remote" IP address in .ovpn file, only TCP port. ... remote a.b.c.d 8443 tcp-client remote 8443 tcp-client remote x.y.z.k 8443 tcp_client How…
  • Site to Site Connection Slow on XGS116 and XGS2300 with big Files

    Hi there, I have a site to site Connection from a Site A XGS116 1GB/300MBit to a Site B XGS2300 1GB/1GB. First i use encryption IKEv2. With this Configuration it was not possible to work with the Shares. Click on a File with about 300 MB, a blue…
  • sophos received IKE message with invalid SPI from other side

    I 'am creating a VPN IPSEC Tunnel between 2 BRanchs ( partner local and eleader distant ) The distant site ( central ) forced us to use the same parametrers that he is using with other branchs , unfortunatley after setting all the configuration , the…
  • XGS Central registration via a Parent Proxy

    Hi Guys, We use an XGS firewall with a parent proxy. Unfortunately, the registration in the Central Portal does not work as a result. Is it somehow possible to realize this? Best regards Marcel
  • import export issue

    Hi All, i would like to submit for all uf us my issue while exporting the configuration from xg 330 and imported to vm sophos xg and there are only 39 rule got imported out of 45, ipsec tunn not got imported no static routes got imported , after with…
  • Old and actually fixed bugs under Central Firewall are back......

    Hey, this is tiring.... 3 old bugs that were actually already fixed are unfortunately back 1. Importing a ruleset from an existing firewall into Central no longer works. Old Case ID was 04997580 (opened on 03/22) 2. Central Synchronisation of…
  • Sophos Connect SSL authentication with Windows Server Radius

    Hello, we have an XGS 2100 (SFOS 19.0.1 MR-1 Build365).and we tried to configure (without luck) SSL Authentication using a Windows Server Radius. We always get "authentication failed" using "test connection" button (I know that pap must be enable…
  • Sophos VA in Azure and S2S VPN with SonicWall - the tunnel periodically falls

    Hello We have new Sophos VA VM in our Azure (19.0.1 MR-1-Build365 + latest fixes, raised from Azure market). Office LAN: 10.50.0.0/24, static IP on SonicWall WAN Azure VPC: 10.0.172.0/24 (Sophos VA WAN) + static public IP and 10.0.0.0/24 (Sophos VA…
  • XG RED unified firmware enabled vs not enabled

    https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/SystemServices/RED/index.html For XG's on SFOS 19.0.1 MR-1-Build365 + RED firmware 3.0.008 with "Use RED unified firmware" not enabled and "Firewall RED…
  • Our Sophos FW receiving a Failed Patter Update

    Here is the logs as well under /log/u2d.log DEBUG 2022-10-08 04:52:37Z [14462]: Received md5sum : 87b1da28f8b17ac15df58af0a4a16011 DEBUG 2022-10-08 04:52:37Z [14462]: Received module : sysupdate DEBUG 2022-10-08 04:52:37Z [14462]: Received cv : 0 DEBUG…
  • Wifi faster than ethernet

    Hi, Maybe someone can help me with issue I'm facing. I have fast internet connection (around 800 mbps download) and the thing is that I can't pass 20 MB/s when downloading software from Microsoft site using ethernet. When I switch to wireless I'm…
  • Internet and Reporting issue with XGS87

    I have encountered a remote case with this firewall, the setup and issue is as follows: Firewall model: XGS87 Firmware: SFOS 19.0.1 MR-1-Build365 This is a new firewall that we have deployed. Before installing this firewall the customer faced no…
  • Weird Issue Accessing Netgear Router Web Interface

    Hello World, I am running Sophos SFOS 19.0.1 MR-1-Build365 I have a strange issue. I have a separate network for wireless. 10.1.1.1 and another network for my LAN 10.2.1.1 I can ping every device from each network. However, when I attempt to access…
  • Cannot delete certificate - "Couldn't delete certificate. It's in use in an IPsec, L2TP, or SSL VPN connection."

    I am on 19.0.MR1 I have an uploaded certificate which is no longer needed. It was used in WAF rules, those were deleted a couple of weeks ago. However I cannot delete the certificate, I get the red box at the top with " Couldn't delete certificate…
  • XG-HA-Cluster: License on Master after failover - can the former auxilary stay primary?

    Hi, I've recently read that, there is an issue with licensing after failover. Could you help me here? We have a XG-125 Active-Passive Cluster (V19.1 Firmware) and currently the former auxilary is "primary". The former "primary" holds the licenses…
  • User import and export issue in Sophos XG330 (SFOS 19.0.1 MR-1-Build365)

    Dear All, We want to export users. we have trying to export from UI portal. in the exported data does not find description and groups. is there any other way to export users with description and with their groups?
  • SSL VPN - client won't re-connect unless I re-install the Sophos Connect app

    Firewall Site: - XG125w (SFOS 19.0.1 MR-1-Build365), IP Range 192 - Network range: 192.168.0.X Remote Client Details: - Network range: 192.168.5.X - Sophos Connect Client Version: 2.7.75.0506 - Client OS: Win10 Pro 64bit (latest Windows…
  • "§" not working in WPA2 PSK

    Hello, we have changed the PSK from our WPA2 Personal WLAN to a password which ends with an "§". After this many devices could not connect to it, wc_remote.log says: "STA WPA failure", reason_code = "2" We have tested this with SFOS 19.0 GA, and SFOS…
  • DNS Host Entry doesn't work for some VLANs

    I recently updated to SFOS 19.0.1 MR-1-Build365. Since the update my DNS host entries aren't working on all VLANs except the VLAN the firewall is connected to. They were previously working in 18.5 and I haven't made any configuration changes. I have…