Browse By Tags

  • Outbound UDP port 443 blocked

    We have a Sophos XG135 firewall running SFOS 20.0.1 MR-1-Build342). We have a cloud 8x8 VOIP phone soultion which is having intermittant audio issues. We have been asked to run their network diagnostic tool which is reporting back UDP port 443 outbound…
  • Route IPv6 to DMZ

    Hi there, we have a /64 subnet (with gateway) and a /56 assigned by the ISP. No PD in place. I've assigned an address from the /64 subnet together with the gateway to the WAN interface, which is now reachable via IPv6. I'd like to assign IPv6 Addresses…
  • Linked NAT rule for LAN to LAN traffic?

    Hello all, I have inherited a firewall that has linked NAT rules for LAN to LAN type rules. Is there any need for them (I don't think so as really only required for LAN to WAN), and would it hurt anything if I just left the NAT rules? Thanks.
  • Web Pages Slow to Load

    Referencing this previous post: Webpages SLOW to load That post is over 7 years old and locked, so I am posting here. I recently started having this same issue...Web pages take 30+ seconds to load for all users on network A number of coincidental…
  • Cellular WAN constantly showing up and down, but never *actually* going down

    Brief description of my setup: WAN1 is a hardline connection. WAN2 is a cellular 5G connection, using a standalone antenna and modem. SD-WAN 1 is configured for general internet traffic, where WAN1 is the default and WAN2 is failover, using TCP…
  • Assign a second public subnet to DMZ

    Hi, I'm using a XGS116 with SFOS 20.0.1 MR-1-Build342. I've got a public subnet 1 (2.1.1.0/30) assigned by the ISP. 2.1.1.1 is their gateway. 2.1.1.2 is used as static IP of PortF1 (ISP1). I've got a backup connection on Port3 (ISP2). I've defined…
  • Can't contact local DNS from SSL VPN (with 2 WAN)

    Hello, I'm not an expert (for the moment) on Sophos. For a customer that has an XG Firewall, he asked to configure a SSL VPN connection. As I already done this some years ago on a privous Sophos Router, it should be possible ;-) But the LAN/WAN…
  • XG125 Blocking Programs or Ports

    Hi, Is it possible that an XG125 Firewall can block programs and TCP/UDP ports for network traffic between a Windows Server and client computers within the same LAN? I know the firewall can block traffic between the LAN and the internet but my question…
  • Integrate synthetic allowlist in a rule without WAF

    Dear community, As a firewall noob I am wondering how to integrate a dynamically changing list of IPs into an allowlist for a specific firewall rule. As a home user I unfortunately have no access to the "Web protection subscription", only "Base Firewall…
  • Change Internet Connection for the Firewall Upgrade

    Hi, Does the firewall use only the first WAN connection for operations like upgrading the firmware, definitions, or load balances in case of multiple WAN interfaces? If it uses only the first wan interface, is it possible to change it? Thanks.
  • Email flow to Exchange server stops

    Sophos XGS 2300 running 20.0.1 Internal exchange server DNAT rule allowing passthru of SMTP traffic to the exchange server. ports 25,465,587. From time to time we stop receiving email. to fix, we reboot the sophos firewall. When it stops working…
  • XGS2100 Throughput

    Hello, I have two sites configured with HA XG2100 firewalls, At both sites 1GBe Port2 is the WAN connection this is a 100/100 circuit typically usage is around 30%, 1GBe Port 6 is an MPLS L2 1Gbp/s Circuit that connects both sites. All LAN traffic is…
  • Cannot send Viber attachment on desktop version but successful on mobile version

    Cannot send Viber attachment on desktop version but successful on mobile version. Just migrated from XG210 to XGS2100 with latest firmware SFOS 20.0.1 MR-1 Build 342. No problem in fresh setup on XGS2100 both desktop and mobile version on Viber. Thank…
  • SFOS 20 IPV6 over PPPoE

    When will ipv6 be supported over PPPoE ? When I use any other router / firewall I am able to get IPv6 over PPPoE just not via Sophos
  • Please allow rule renaming

    HELLO When we create a routing rule (or other items that do not support renaming), and feel that the name is unreasonable or needs to be changed for other reasons, we find that the name cannot be modified and can only be rebuilt or copied. This is a…
  • VoIP-Telefonanlage hinter XGS

    Hallo zusammen, ich habe hier folgendes Scenario: Vodafone Anschluss mit fester IP ( 145.253.111.21 - nicht REAL). Jetzt soll eine TK-Anlage über VoIP angebunden werden. Da 4 IPs vorhanden sind, habe ich am Port 2 der Sophos eine 2. öffentliche und…
  • LAG configuration

    Hello, So I have a weird scenario and I need second opinion. We have two firewalls Active Passive and two switched Active Active The first switch was configured to connect to the primary firewall on a port F4 and this port has vlan on it,…
  • Hilfe / Meinungen bei Zonenaufteilung XGS116

    Hallo zusammen, ich möchte für unser kleines Familienunternehmen nächste Woche die Sophos XGS116 einrichten, weil wir vor kurzem einen kleinen Sicherheitsvorfall hatten und ich gerne unser Firmennetzwerk ein bisschen ändern bzw sicherer machen möchte…
  • Two Lan Network for Two different WAN

    Hello Guys, I've tried to search, but without any luck. Basically I have a very simple configuration: LAN1 192.168.X.X --> WAN 1 Now I would like to modify the configuration, in this way: LAN1 192.168.X.X/24 --> WAN 1 LAN2 192.168.Y.Y/24 --> WAN…
  • Externet Pentest

    Hallo zusammen, Ich stehe vor einem (mir) etwas neuem Problem. Einer meiner Kunden möchte einen externen Pentest durchführen, dieser Dienstleister fragt an ob wir seine IPs für den IPS Scan whitelisten können. Mein Google-Fu hat mich soweit geleitet…
  • INTERNAL NETWORK ACCESS TO EXTERNAL IP

    Hello, we have implemented the Sophos firewall and we are facing a serious problem, no matter how much we configure the internal network IPs, it does not access the external IP, Could you help us? Grateful
  • WAN/Internet failover confusion and Starlink

    I've got our firewall (XGS2100) connected to 2 Internet connections. One is a local wireless internet provider we've been using for years (as its a very good deal) and recently a Starlink connection to replace the woeful DSL and 4G connections. I had…
  • Network Configuration Issue

    ##### Aktualna konfiguracja **Router:** - Adres IP: 192.168.1.1 - Maska podsieci: 255.255.255.0 **Sophos:** - Interfejs LAN: 192.168.1.79 - Interfejs WAN: 192.168.2.1 **Reguła wyjątku listy ACL usługi lokalnej:** - Strefa źródłowa: WAN - Sieć źródłowa…
  • Replaced firewall with xgs 2300 - video server playback not working

    We recently replaced all our xg230 with xgs 2300 firewalls. Geovision Video server is on a dmz with port forward rule and NAT rule. Remote playback and viewlog you can't connect to them. Live view works fine. Other sites no issues. Firewalls are setup…
  • A phone is receiving ip address of the firewall when it connects to the network

    Good day We have an XG 35 ON VERSION 20.0.1 There is a phone that is connecting to the network.. and when it connects the network it is getting 192.168.10.1 which is the ip addresss of the firewall .. Our DHCP is the firewall , and the DHCP pool…