Browse By Tags

  • Sophos XG - Redirect internal DNS traffic to different WAN interface

    Hello, I have a XG with two interfaces in WAN zone (because I need a gateway for both) in a data center housing scenario. Let's call the interfaces WAN-int and WAN-ext. WAN-ext has a public IP-address and WAN-int has a private IP-address. …
  • how to add dns to sophos xgs firewall

    hi all, on the sophos xgs firewall on the diagnostics i can ping 8.8.8.8 but i cant ping google.co.uk under "network > dns" i have added a few dns ips in there but when i go back to diagnostics ping, i type in google.co.uk, ipv4, select my wan interface…
  • DNS Konfiguration wie in Best Practice beschrieben aber im DNS Log nur IP der Sophos

    Hallo Zusammen, ich habe die DNS Konfiguration wie in KB-000034974 - Sophos UTM: Best practices for DNS Configuration beschrieben eingestellt. Das DNS Logging am Windows DC (2016) ist aktiv, jedoch steht bei jedem Eintrag die IP der Sophos. Woran…
  • PiHole macht surfen extrem langsam - DNS Einstellungen falsch?

    Guten Morgen zusammen. Ich betreibe zuhause seit einiger Zeit eine UTM mit Home-Lizenz mit 4 aktiven Schnittstellen (WAN, LAN, Guest & IoT). Vor einigen Wochen kam dann ein Raspberry Pi Pihole dazu, den ich versuchsweise am WAN-Port bei der Fritzbox angestöpselt…
  • DNS server behind XG firewall NAT

    Hello community, Recently i was asked to migrate an existint configuration from a router to XG firewall and here is the scenario : an application running in my local server with the name : transmission.local.co IP@ is 192.168.62.11 DNS serve r…
  • Can DNS Spoofing be detected

    Hi, Can DNS Spoofing be detected.
  • Sophos XG making a significant amount of DNS queries to www.google.com.*

    I recently added Pi-hole as the DNS server for Sophos XG itself, and I’ve noticed in my Pi-hole logs that Sophos XG is making a significant amount of DNS queries to various google.x addresses, such as google.de, google.com.pr, google.to, google.com.af…
  • SSL VPN use Windows DNS server fail

    I switched from a workgroup to a domain. I was using the UTM as a DNS server with static network definitions for the servers that are hosted behind the UTM. Some of the servers are accessible from both local and external clients so I went with the second…
  • Sophos xg can't resolve own hostname and internal server

    Hello all, I am currently trying to configure Sophos xg to replace my Fritzbox. From problems with certificates, I have become aware that my DNS resolution for internal hosts and the xg itself is not working. Currently I have only a test client, which…
  • Outlook and certificate "issue".

    Hello all, As the UTM 9.705-7 we are using was setup by an MSP and at that time we had Exchange 2010, on premise as well. We've since moved to Exchange online and I handle all the Sophos items now. Lately we have random users receiving the following…
  • New install XG86w having dns issues

    Wr have a brand new XG86w that we are connecting to Comcast. The comcast modem is in basic bridge mode. The problem is that about every 10 minutes DNS fails. We cannot ping anything from the firewall. I have tried comcast default DNS, Google DNS and OpenDNS…
  • How to migrate from a workgroup to a domain environment?

    I decided to complicate my life (further) by switching my home-office/lab from a workgroup to a domain environment. I have both local and remote web servers and email servers. The Sophos UTM is currently acting as my DNS and DHCP servers. I am also using…
  • Block DNS resolution between VLANs

    I'm looking to use the built-in DHCP and DNS server on the Sophos XG on my "Main VLAN" but I don't want other VLANs to be able to do any nslookups for the host entrys. Today VLAN1 has it's own DHCP and DNS server and the other VLANs uses the Sophos…
  • DNS dos not resolved

    we hosted the server on IIS in the internal network and I assigned a domain name like app.example.com but the problem is while trying to access from outside the network using domain name(app.example.com) the website has not loading but while trying…
  • {dnscache} dnsd keeps restarting

    Running XG 18.0 MR5-Build586 on a pair of SG230's in HA (Active-Passive). We use the XG as a local cache and DNS relay, since we rely on AD DNS hosted in our AWS Virtual Private Cloud. We have DNS request routing setup so that only internal domains are…
  • Sophos XG v18 - DMZ challenges

    As a quick background, I have been working with firewalls for about 15 years (Cisco PIX, Cisco ASA, and recently SonicWall TZ and NSa). I have been working on and off with Sophos XGs for about 2 years now so I am familiar with them but they are definitely…
  • Problems connecting to internal app server from SSL and IPSEC VPN using Sophos connect

    I am using XG210 (SFOS 18.0.5 MR-5-Build586) and Sophos Connect 2.1.20. SSL VPN and IPSEC VPN for Remote Access is configured as "use as default gateway" forcing all remote traffic through the XG. Remote users are able to access LAN resources, that…
  • Internal DNS servers, Zone DNS option and rules

    Sophos XG106 (SFOS 18.0.5 MR-5-Build586) I have set up several own DNS servers and added them to XG DNS settings. XG DHCP service provides those DNS servers to our clients. Clients are separated in different zones, all with their own WAN rule and…
  • Routing Site-to-Site VPN Traffic on same Domain Computers

    Currently, I have a Site-to-Site VPN, with split tunnels to specific IP's and networks, setup on both Sophos firewalls and they are working fine. BIGGEST THING TO REMEMBER , the branch office needs to have their computers on our internal Domain. The…
  • block all internet DNS services except 3

    Hello, We want our lan users to not be able to change their dns settings on their computers or browsers to use other dns services available on the web. We want to only allow access to these two dns servers : 208.67.222.222 and 208.67.220.220 (these…
  • Change UTM DNS Server to other Internal DNS Server

    Hello, I saw already the DNS Best Practice Article and UTM Help Section, but still have questions how to change my DNS Server correctly. At the moment I use the utm as dns server, and I have already created all my internal devices as host objects with…
  • Sophos Connect DNS issue for remote LAN devices

    Having issues resolving LAN devices. The Sophos Connect clients have proper DNS servers assigned, and reflected in connection. DNS device access is allowed for VPN zone. No remote devices will resolve, NSLOOKUP example: *** UnKnown can't find…
  • The Sophos XG135 is not returning any DNS name resolution if we don’t “reconnect” the RJ45 cable.

    Hello ! Can someone support me in a “weird” issue please ? Problem : The Sophos XG135 is not returning any DNS name resolution if we don’t “reconnect” the RJ45 cable. When any PC on Windows 10 boots, they cannot access the DNS server which is our…
  • WAN Failover does not work on XG - DNS?

    Hello...We have an XG firewall configured with (2) WAN interfaces. The primary is a cable connection from COX. We have a second one configured as a Backup in the WAN link manager that is pointing to a CradlePoint router with a Cellular SIM installed.…
  • Ping from VLAN only with FQDN

    Hello Community, i have a problem. on my xg i have 2 Networks: 1. 172.20.10.x (Default LAN) 2. 172.20.8.x (VLAN8) Both have his own DNS Server: 172.20.10.x --> DHCP with DNS 172.20.10.1 172.20.8.x --> DHCP with DNS 172.20.8.1 i added all…