Browse By Tags

  • Using firewall rule XXXX -> ANY -> Internet causes YouTube connection speed to drop below usable rate on that device / network

    Hello Sophos Community, I noticed a strange phenomenon when I wanted to set up a guest network. Since this network has no access to other networks and should be able to browse the internet freely, I created a firewall rule as follows: Guest network -…
  • NAT Rule not working

    NAT rule is not working. Tried both ways (DNAT / Firewall+NAT Rule). My WAN interface named BSNL and LAN interface is on Port #8..
  • Route all Netflix traffic through VPN

    Hello, Hoping I can get some help - tried searching but its still not 100% clear to me so hopefully someone can provide some insight. LAN > multiple ports , 1 feeding a linux box which has my server that handles things like plex etc AP device > feeds…
  • Traffic wird Denied obwohl es erlaubt ist

    Hallo, wir hatten gestern einen Stromausfall und seitdem geht ein Teil der Telefonie nicht. SIP Module ist ausgeschaltet. Regel habe ich auch einmal neu gemacht. Es ist eine XGS126 (SFOS 19.5.2 MR-2-Build624). PCAP funktioniert leider nicht zeigt…
  • VLAN to LAN Rule

    Hallo zusammen, ich habe folgendes Problem bei meinen VLANS: Ich habe insgesamt 4 VLANS erstellt. Ich habe die jeweiligen Zonen angelegt und den DHCP für jedes VLAN. Die Geräte im VLAN bekommen auch die jeweilige IP zugewiesen. Es gibt eine…
  • Can't establish HTTPS connection - INVALID_TRAFFIC

    Hi all, I'm struggling with an issue since few days. I'm using SFOS 19.5.3 MR-3-Build652 and I can't establish a TLS connection between two hosts on different VLAN. I've a firewall rule that allows the hosts to communicate each other, the first…
  • Regras para nao permitir acesso a internet

    Bom dia a todos. Alguem sabe se é possivel criar uma regra para nao permitir que alguns dispositivos acessem a internet somente consigam acessar a rede interna da empresa. Estou pensando em pegar os dispositivos pelo MAC e criar a regra para que…
  • Rule and Policies Order Best Practice

    Hello Friends, I just using Sophos Firewall XG310 SFOS 19.5.3 MR-3. All I know that order/sort of Rule and Policies position is affect to how Firewall Treatment on traffic flow. Kindly need advice, if I have a set of rule as below pict, what is the…
  • Struggling to connect to CCTV system from the WAN

    Good Day, Could anyone assist me? I have created a VLAN for CCTV to sperate from the company network. Want to allow the CCTV to be connecting from the WAN Port from our ISP to use the Public IP so that we can monitor the CCTV remotely without VPN…
  • my network exposed

    hello today i tried to ipscan my network with a very larg range to check my network, the result shows there are many ranges that i am not aware of and they are not in my network, i ping them and i was able to run some ips in the browsers shows they…
  • 3CX Full Cone error

    Hi I have a XG and im trying to get 3CX working correctly. I have nat and firewall rules set but when i run a test from 3cx I'm getting the full cone error i cant see what I'm missing
  • ipv4 und ipv6 Regelwerk tatsächlich getrennt?

    Ich bin gerade am Einrichten eines XGS 2100 Clusters. Dabei fällt mir auf dass das Regelwerk für ipv4 und ipv6 komplett getrennt angelegt werden muss? Ist das wirklich so? Das wäre ja eine Katastrope. Warum kann man die Regeln nicht gemeinsam pflegen…
  • Firewall Rules - Why don't they default to "none" for the Rule Group.

    I appreciate the fact that Firewall Rules can be grouped, as this makes for more flexibility in the sorting and managing of rules versus not. However... the default option for firewall rules is "Automatic" which if you forget to change, jams it into the…
  • InactiveRpcError when using Sophos FW

    A few users in our network use Python & Java scripts to connect to some services on AWS. The scripts work fine when bypassing the Sophos FW or using mobile hotspots. But when using Sophos the users see errors like this in their terminals: Exception…
  • Unable to access company websites inside the local area network

    Good day we are unable to access company websites inside the local area network. The websites are hosted outside our LAN.. We can ping the public IP address for the websites. Traceroute to the public IP address of the websites is completing And…
  • Magenta TV XGS126 Firmware 19.5.3

    Hallo, wir haben eine XGS126 mit Firmware 19.5.3 im Einsatz. Für ein Subnetz wollen wir Magenta TV nutzen. Die ausgehende Regel: WAN - Internet IPv4 group - any ermöglicht Magenta TV. Schränken wir ausgehend ein auf: http, https, IGMP, funktioniert…
  • Opening a port for a web app connecting to a database

    I have a web App opening with localhost:8443 and connecting to an SQL database in another server at port 1433. I have installed another DB in the same server where the WebApp is. When I try to connect to the database that is in the same VM as the WebApp…
  • Frage zur Sophos XG210

    Hallo, ich bin gerade dabei mich etwas mehr mit der Sophos zu beschäftigen. Nun habe ich wohl ein kleines Problem. Unser LAN wurde erweitert und die Sophos ist für das neue LAN das Gateway. Wenn ich jetzt aus dem alten LAN ins neue LAN einen Ping mache…
  • Firewall block with reason Heartbeat but User and Computers have green HB

    We have a firewall rule allowing access to an internal server. Source and Destination HB must be green, also the rule has "Block clients with no heartbeat" enabled. The rule exists unchanged for years but recently we noticed users complaining that they…
  • Docker L3 network routing notworking Sophos XG fireall

    Hello! I'd like to ask for your help, I've been using this great firewall for several years, but now I'm stuck. I have a small network at home in which I installed a docker host for testing purposes. I have found the best way to allow the docker containers…
  • Firewall-Härtung - Frage zu Filtern + Logging

    Hallo zusammen, eine bestehende UTM-Firewall (9.7) Umgebung, die aktuell zum größten Teil mit ANY-Regeln arbeitet, soll optimiert (gehärtet) werden. Das Problem dabei: Einen Überblick über den Traffic zu bekommen, ist nahezu unmöglich, da via ANY…
  • Strange behaviour in SSL VPN , Firewall traffic "fwrule=60001"

    Hi Community, i'm facing a strange problem in a sophos from one of our customers. The SSL VPN Has beenstruggeling with long first loading times in the browser, for example we go to google.com, takes about 40 seconds to load, so i thougth it was a…
  • Allow Port in Sophos Firewall

    Hi Everyone, I am new to Sophos firewall and I dont know much about this. Can any one tell me how to allow following port in Sophos XG135 (C1B0Cxxxxxxxxxx) CLOUC uses the following Ports HTTP, HTTPS and 9443 for the web console 5060 and 5061 TCP…
  • VPN Firewall Rules - Match Known Users issue on Sophos XGS v19.5.2

    Hi, We have 2 types of IPsec and L2TP VPN users. one which have Intercept X on their systems and another which are normal users without Intercept X. Now we want to restrict users to access only from their specific machines. Like the users which have…
  • Webserver Protection - Zertifikat ist nicht auswählbar

    Moin, ich muss mich zum ersten Mal mit der Webserver Protection auseinandersetzen. Dabei habe ich das Problem, dass ich beim Anlegen einer neuer Firewall Regel, das Zertifikat nicht auswählen kann. Was habe ich bisher gemacht? 1. Das Zertifikat…