Browse By Tags

  • Firewall policy template

    Hi, Is it possible that customer that have 20 firewalls managed on sophos central create template and apply to all firewalls. Is there any detail documentation about how that works? Regards,
  • Sophos FW rule from version 17.5 question

    Dear All, Would like to seek for your help, i have the following firewall rule from Sophos 17.5, i would like to create the same rule in Sophos version 19.5, how do i create it under firewall rule + NAT rules for the following ? any help would be…
  • How to change default SNMP port?

    By default, the agent's port is 161 and the manager's port is 162, but many internet operators here in Brazil leave this port blocked, which makes it impossible to access the firewall's SNMP. How to change this default port?
  • SSL VPN

    Hi !! im having a problem whit my SSL VPN´S, i have my SSL VPN whit the "USE as Default gateway option on" In my NAT rules i Have my SSL VPN doing MASQ to original, and in firewall rules i have permitid the SSL VPN to access my LAN´S and the WAN on…
  • SG230 - After change WAN source, only google and ping works.

    Dear Users, I have an issue with sophos SG230. From couple of days , we tring to remove lancom router, and left only SG sophos firewall as DHCP server (before it we have vodafone modem). Unfortunetly after we connected the cable directly from Vodaphone…
  • XGS 19.5 Firewall rules enable/disable via cronjob

    HI, if it possible to enable/disable firewall rules via cronjob. The customer wants certain firewall rules to be deactivated every evening, the rules are activated manually upon request. I was able to do that on the SG, it was possible to turn on…
  • Ping between IPSec Tunnel Site-to-Site

    Hello guys, I have IPsec Tunnel Site-to-Site with this lans: 192.168.22.0/24 192.168.26.0/24 On the lan 26.0 i need to reach 1 machine and that machine got the ip 192.168.22.140. On diagnostic of firewall i can ping that machine but on CMD…
  • SD WAN ISSUE

    Hello, i have issue with v19.5 , i have server in DMZ zone there's a connection between the server the other in other subnet and i made a rule for this, and working fine, and there's rule LAN TO WAN for this server , the problem is when i create SD…
  • [XG V19] Route a single host through a different WAN

    I need to route a single host through a WAN that is not the default wan. In the previous firmware version I just had to create a firewall rule and specify the gateway, but now...I'm lost. I've followed this article Sophos Firewall v19: How to Choose…
  • Sophos SG310 -Interpreting Dropped Packets in Firewall Log

    We have a Sophos SG310 Firmware v9.714-4. I am trying to figure out some issues and have been reviewing the firewall log but I'm unable to something out. Below is an example of a dropped packet listed in the Firewall log. 2023:02:24-01:14:33 utm-wi01…
  • Filter User-based Firewall rules for User/Group "Any"

    Is it possible to display only those firewall rules that have this setting for user/group "Any"? I could not find a filter that worked. we're on SFOS 19.0.1
  • Setting up FTP and FTP-bounce attack

    I'm trying to access an FTP server located in our Server Zone from our DMZ Zone (passive mode). When the server initially responds from port 21 to the initial connection, the connection is being blocked by Sophos XG - "FTP-bounce attack" but I have…
  • virtual Sophos FW acting as Internet proxy client computer could not access Internet

    Dear All, I currenty running a virtual sophos FW in esxi with version 19.0.1 MR-1-Build365, and i already have another internet gateway which using palo alto, this sophos i want to act as Internet Proxy, in client computer its will need to have below…
  • Unable to access a service using SAP router outside the network

    Good day Team Using Sophos XG 310 V19 Users are not able to access a service using the SAP business, outside the local area network, using the SAP router. We use code nwbc. We have created a DNAT for the server. we getting the error below
  • SOPHOS web service issue

    Hello I have SOPHOS XG 19.0.1 firmware which i have upgraded version due to facing issue, one web which was working earlier suddenly stop to work and not getting access from the public network. I took support from tech, but they also not able to understand…
  • Can't get MS Always-on-VPN working over XG

    I'm migrating from Sophos UTM to Sophos XG ( SFOS 19.5.0 GA-Build197 ) and I cannot get my work machine, which uses MS Alwys-on-VPN, to conmnect when I switch between the UTM and the XG. On the XG: Port 1 is the LAN, Port 2 is the WAN. I have a work…
  • FTPS, without NAT (DMZ-LAN) no TLS connection established on Port 21 possible.

    Hi there, I'm struggling with a problem that i don't really understand. In the DMZ is SFTPGo App, which provides a FTPS server. From external (NAT) through port 21, works TLS or unencrypted connection. From internal, although test LAN DMZ to SV is set…
  • Bitdefender VPN clients still blocked after adding vpn protocols access thru firewall?

    After adding firewall rule to allow protocols , Bitdefender vpn clients on desktops still fail, live logs show no blocking of the protocols after the rule addition also? Has anyone experienced this issue previously and resolved it?
  • Sophos XG and Adguard Home on Docker Synology

    I have a synology server at home with adguard home. I created the rules in sophos xg (I think I missed something) because when the lan connection uses the ip of the synology server where adguard is, I can't access the website, when I change the dns server…
  • mysql server port 3306

    I m facing in issue to accessing my sql server database on port 3306 by app sql front . I created rule in firewall from internal lan to my dmz server for mysql port 3306 . Rule Source -Lan Device -my System Ip Destination -DMZ Device - My Sql…
  • ACL Violation when attempting WAN to LAN NAT v19.5.0

    Hello I have searched and can see others have this issue, however none of the solutions have worked for me so far. I have followed the steps at https://docs.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies…
  • Sophos V19.5 - No SNAT but still running ?

    Hello, I'm using XG135 with latest firmware SFOS 19.5.0 GA-Build197. My fw rule for outgoing traffic to Internet like this (rule ID 10): When I look into NAT rule, I see that the SNAT rule for outgoing traffic to Internet has the number of usage…
  • Whitelisted Access to Internet for vLAN - Sophos Firewall

    Hi, We have just started using Sophos FW and having some difficulties creating Rules. We have two vLANs vLAN10 and vLAN20. We need to allow vLAN10 to have full access to the internet whereas vLAN20 should have a whitelist, i.e. access to few websites…
  • ROS Sophos

    Hi, I'm new with this equipments, i'm trying to configure VLANS between two equipments (SOPHOS -» Switch) SOPHOS: - WAN - DHCP from ISP router - LAN PORT1 IP: 192.168.100.1/24 - ZONE LAN 1.10 - VLAN 10 - 192.168.10.1/24 - PORT 1 - ZONE…
  • LAN user cant access internal web server through public IP

    Public user are accessing local URL (http://117.x.x.x:3000) successfully, but internal LAN user (192.168.16.10) want to access by public IP , but cant access URL : http ://117.x.x.x:3000, what is the solution,