Browse By Tags

  • Enable Routing for public IP on the Lan Interface

    Hello everybody! Right now I have the situation where I want to have multiple public Servers behind a sophos virtual firewall. For the Sophos i have a seperate public IP. I have a public IP Subnet for the servers that is routed via the public IP of…
  • Create user sophos from API Laravel

    how to create user sophos from laravel API. i'm success create user with API postman, but when i'm implemented in laravel. User not created. Please help me this my script in laravel public function sophos() { try { $url = "">192.168.7.1…
  • New Setup Issues (Fresh Install)

    Hello Everyone, I am a new user of Sophos Firewall for Home, unfortunately I am encountering a few issues. I have managed to get an internet connection on it but I am unable to register it and getting the following error - Can't connect to the registration…
  • Nach Wechsel (SG116>XGS2100) kein Zugriff mehr auf Fileserver (Synology)

    Guten Morgen, ich hatte letzte Woche unsere "alte" SG116 durch eine XGS2100 ersetzt und bin derzeit dran, die FW weiter zu konfigurieren. Ein Problem konnte ich bisher nicht lösen > der Zugriff auf unseren Fileserver (Syno) von mehreren Servern (VMs…
  • Unifi USG behind Sophos XG - vlan config

    Hi, my current network looks like this. This is a double NAT scenario but works quite well. Now I got a Unifi USG for testing purposes. I'd like to add it between the Sophos XG and the Unifi Switch. The Sophos should keep on managing DHCP, DNS…
  • VLAN firewall best-practices / Mode bridge, gateway mode

    Hello, we got 2 new XGS450-firewalls. Currently the configuration is blank. The firewall should manage the vlan traffic. We have 3 branches. They are connected with a cisco mpls-network. Our internet-firewall in the mpls network: Should be…
  • Merging of two incoming lines.

    I have two lines on firewall one is of internet line and one is of local line on which a specific website works. When we search that specific website that 2nd line should come into picture, but currently both the line are active but that website is not…
  • External web site does not open.

    Hi experts, I have an external web site hosted in the AWS, and the DNS domain name is registered in my local DNS server (Windows 2019 with AD and DNS). I have configurated the DNS options in Sophos XGS as shown below. The website does open for internal…
  • DHCP Static IP mapping for same client multiple networks - FW 20.0.1

    Hello, I refer to RE: DHCP Static IP mapping for same client multiple networks? With the update from SFOS 20.0.0 GA-Build222 to SFOS 20.0.1 MR-1-Build342 the Sophos system dhcp conf-generation-method has been set to old again: console> system…
  • SNMP Collection - Sophos XG 19.5

    hello, I noticed that when I execute the `snmpwalk` command on the OID `.1.3.6.1.2.1.31.1.1.1.18` (ifAlias), the result comes back empty. When I execute the OID `.1.3.6.1.2.1.2.2.1.2` (ifDescr), it returns the interface name. For example: eth7. …
  • Outbound UDP port 443 blocked

    We have a Sophos XG135 firewall running SFOS 20.0.1 MR-1-Build342). We have a cloud 8x8 VOIP phone soultion which is having intermittant audio issues. We have been asked to run their network diagnostic tool which is reporting back UDP port 443 outbound…
  • Route IPv6 to DMZ

    Hi there, we have a /64 subnet (with gateway) and a /56 assigned by the ISP. No PD in place. I've assigned an address from the /64 subnet together with the gateway to the WAN interface, which is now reachable via IPv6. I'd like to assign IPv6 Addresses…
  • Linked NAT rule for LAN to LAN traffic?

    Hello all, I have inherited a firewall that has linked NAT rules for LAN to LAN type rules. Is there any need for them (I don't think so as really only required for LAN to WAN), and would it hurt anything if I just left the NAT rules? Thanks.
  • Web Pages Slow to Load

    Referencing this previous post: Webpages SLOW to load That post is over 7 years old and locked, so I am posting here. I recently started having this same issue...Web pages take 30+ seconds to load for all users on network A number of coincidental…
  • Cellular WAN constantly showing up and down, but never *actually* going down

    Brief description of my setup: WAN1 is a hardline connection. WAN2 is a cellular 5G connection, using a standalone antenna and modem. SD-WAN 1 is configured for general internet traffic, where WAN1 is the default and WAN2 is failover, using TCP…
  • Assign a second public subnet to DMZ

    Hi, I'm using a XGS116 with SFOS 20.0.1 MR-1-Build342. I've got a public subnet 1 (2.1.1.0/30) assigned by the ISP. 2.1.1.1 is their gateway. 2.1.1.2 is used as static IP of PortF1 (ISP1). I've got a backup connection on Port3 (ISP2). I've defined…
  • Can't contact local DNS from SSL VPN (with 2 WAN)

    Hello, I'm not an expert (for the moment) on Sophos. For a customer that has an XG Firewall, he asked to configure a SSL VPN connection. As I already done this some years ago on a privous Sophos Router, it should be possible ;-) But the LAN/WAN…
  • XG125 Blocking Programs or Ports

    Hi, Is it possible that an XG125 Firewall can block programs and TCP/UDP ports for network traffic between a Windows Server and client computers within the same LAN? I know the firewall can block traffic between the LAN and the internet but my question…
  • Integrate synthetic allowlist in a rule without WAF

    Dear community, As a firewall noob I am wondering how to integrate a dynamically changing list of IPs into an allowlist for a specific firewall rule. As a home user I unfortunately have no access to the "Web protection subscription", only "Base Firewall…
  • Change Internet Connection for the Firewall Upgrade

    Hi, Does the firewall use only the first WAN connection for operations like upgrading the firmware, definitions, or load balances in case of multiple WAN interfaces? If it uses only the first wan interface, is it possible to change it? Thanks.
  • Email flow to Exchange server stops

    Sophos XGS 2300 running 20.0.1 Internal exchange server DNAT rule allowing passthru of SMTP traffic to the exchange server. ports 25,465,587. From time to time we stop receiving email. to fix, we reboot the sophos firewall. When it stops working…
  • XGS2100 Throughput

    Hello, I have two sites configured with HA XG2100 firewalls, At both sites 1GBe Port2 is the WAN connection this is a 100/100 circuit typically usage is around 30%, 1GBe Port 6 is an MPLS L2 1Gbp/s Circuit that connects both sites. All LAN traffic is…
  • Cannot send Viber attachment on desktop version but successful on mobile version

    Cannot send Viber attachment on desktop version but successful on mobile version. Just migrated from XG210 to XGS2100 with latest firmware SFOS 20.0.1 MR-1 Build 342. No problem in fresh setup on XGS2100 both desktop and mobile version on Viber. Thank…
  • SFOS 20 IPV6 over PPPoE

    When will ipv6 be supported over PPPoE ? When I use any other router / firewall I am able to get IPv6 over PPPoE just not via Sophos
  • Please allow rule renaming

    HELLO When we create a routing rule (or other items that do not support renaming), and feel that the name is unreasonable or needs to be changed for other reasons, we find that the name cannot be modified and can only be rebuilt or copied. This is a…