Browse By Tags

  • Confused rule id and broken WAF rule.

    Hi, I'm having trouble with the WAF, XGS 2300 v19.5.1 I add the webserver web .xxx.xxx - it has policy ID 129 . But if I go to web .xxx.xxx in the log it shows that web.xxx.xxx has policy ID 43 . I get a 503 error But the policy ID 43 is spsluzba.xxx…
  • Central Reporting - is it really working?

    I keep hearing about the Central Reporting and how all the detailed logging is available through it, which has plenty of data points and filters. We are subscribed to Xstream Protection, which includes Central Orchestration, which includes 30 days of…
  • Message: Reports disk Usage reached 91% exceeding the higher watermark of 90%

    Hi We're receiving notification almost every day that is stating Message: Reports disk Usage reached 91% exceeding the higher watermark of 90% But when I ssh to it, it shows me 86%. I receive multiple emails in a same day. …
  • Firewall logs - where?

    Log Viewer > Firewall goes back by 10 days or so. I need to retrieve Firewall logs for a period of 2 weeks starting 20 days ago. I've learned that XG(S) do not store log files for Firewall rules. From other posts I've also learned that I should use…
  • Reporting on Peak Concurrent Users

    Hi Sophos, I'd like to generate a view and report on how many users are concurrently connected to the Sophos Appliances in operation so that we can spec for a replacement unit. IS there such a feature available? We are running SFOS 19.5. We…
  • Sophos XGS Firewall: Count of dropped sessions on WAN interface

    Hello, are there any options to see the count of the dropped sessions on the WAN interface over a time period? best regards Harald
  • Clearing Zero-Day Protection log

    Running SFOS 19.5.2 MR-2 on an XG310. In the Zero-day protection section of the Control Center, it shows 0 Recent, 274 Incidents, 330 Scanned. When I click on that, it goes to the Zero-day protection logs, and I get two pages containing a total of 38…
  • Diagnostics>System graphs too slow on Firewall with many network interfaces

    On our XG430 firewall we have some interfaces only the active ones are ~40 VLANs, ~40 REDs, ~30 virtual WiFi networks and adapters, ~10 physical interfaces Currently I monitor CPU load from time to time. Unfortunately, due to all graphs are preselected…
  • Any way to get the real bandwidth Sophos XG under connections ?

    Got a Sophos XG Home 19.5 as a VM under KVM and somehow it is bothering me that I do not get the real bandwidth under connections. Lets say I make a download with 4 Megabytes /s, under connections it will show me only something like 2000 KBits/ s, no…
  • Sophos XG firewall 19.5.0 Logs are not updating on GUI log viewer

    logs are not updating on GUI log viewer dis space is not high all services is also running, kindly help how to identify this issue and what action have to take to resolve -
  • Sophos XGS Firewall reports suddenly stopped working

    Hi, We are facing issues in report generation. I've checked all the logs and all things seem normal. PFB: Regards, MAS
  • Keine Tagesberichte von SG210

    Hallo Sophos Community, wir haben 2x SG210 (Firmware: 9.714-4) Firewalls und bekommen seit einiger Zeit keine Tagesberichte bzw. Wochenberichte von der Firewall mehr zugesandt. Alle anderen Meldungen (Tageskennwort WLAN, Interface Down, Updates usw…
  • VPN Site 2 Site Bandbreite

    Unter Berichte / VPN / IPsec Nutzung wird bei uns nur das IPSec für das Homeoffice angezeigt. Wie kann ich einen Report zu den 2 anderen Site 2 Site Verbindungen bekommen? Speziell interessiert mich hier die Bandbreite /Auslastung unserer SAP Connection…
  • LogViewer log nicht

    Hallo zusammen, ich habe festgestellt das der LogViewer keine Funktion mehr hat. Es sind Regeln vorhanden die mit geloggt werden. Trotzdem kommen keine aktuellen Ereignisse in dem Log an. Der Dienst (reportdb) läuft, Festplattenspeicher ist auch…
  • Signature disk Usage reached 78%

    Hi, we are using Sophos XG-210 now signature disk usage reached 78% is there any way to clear old signature. Thanks satya
  • Sophos XG - Firewall Authentication - 2 Benutzer

    Hallo, ich habe 2 Benutzer die immer wieder im System Log "Authentication" der Sophos auftauchen, die Fehlermeldung lautet: "User XXXXXXX failed to login to Firewall through AD,AD,Local authentication mechanism from XXXXXXX because of wrong credentials…
  • Anwendungsbenutzer werden nicht angezeigt

    Hallo, ich habe eine neue XGS installiert und auf den Clients Sophos End Point und euch die AD mit angebunden. Im Dashboard und Centren sehe ich alle aktiven Clients. Jedoch werden unter Berichte in den Anwendungsbenutzer keine Benutzer angezeigt…
  • Logs do not specify blocked filetypes. Where do downloads blocked by filetype appear in the logs?

    I performed the eicar test where I attempt to download the Eicar virus testfile. The block page shows that the file eicar.com was blocked by filetype. However, the webfilter log shows that the website was blocked, but does not specify that it was due…
  • Syslog configuration

    Hello. We have a FW XG230 which is configuring the Syslog but you want to send the logs through a VPN site to site, the vpn connection is made and policies but it does not send any information. I would like to know where the error could be or how…
  • Firewall XGS 126

    Good morning guys. Sophos XGS Firewall 126. Is it possible to generate a report on accesses to sites by user over a period of 15 days? I can VIEW the accesses, but when I generate the report, it only generates 1 or 2 days
  • Snmp v3 Trap

    Hi guys, I'm capturing SNMP traps from an XG appliance. Everything works fine with SNMP version 2, but I'm unable to capture traps with SNMP version 3 because it seems that the XG appliance is sending an incorrect EngineID. To detect the EngineID, I'm…
  • Bandwidth Mbps Report

    Hello, I'm looking for a report that will show me the bandwidth speed over 7 days, 30 days etc. All I can find are reports that show me the total GB's downloaded. Any idea if a report showing the speed per Mbps is available? I've tried looking…
  • Add or Delete Rules and Audit Logs

    I am using Sophs XG firewall and one of rules was missing, may be someone delete or not. I am not sure. So, Where can I check the logs for add rule or delete rule logs. Thanks.
  • Question about Classification and Category and reporting?

    Hi folks about 4 months ago I asked a similar question and the answer did not clarify the issue. https://community.sophos.com/sophos-xg-firewall/f/discussions/137860/classification-question I see a number ICMP items reported in the daily reports…
  • Bug: Can I exclude domains from being logged?

    Using SFOS 19.5.1 MR-1-Build278 (SFVH (SFOS 19.5.1 MR-1-Build278)) Is it possible to exclude logging certain domains to declutter the logs. Things like outlook.com or Apple.com, or the huge number of tracking/analytics domains. I’ve tried setting…