Browse By Tags

  • IPSec Tunnel: length of ISAKMP Message is smaller than minimum

    Hi, I have one question: a SG 430 9.705-3 is connected to multiple other SGs via IPSec. Today I just put in a new Network in the tunnel config of lets say HQ to Site A The tunnel came up again but was extremely unstable - high packet loss - in…
  • Get SSID of WLAN Client with newer Accesspoints (APX)

    Hello, I'd like to collect and analyze the wireless logs. Older accesspoints send in nice logs like this one: 2020:11:11-17:13:01 <AP_ID> awelogger[9274]: id="4104" severity="info" sys="System" sub="WiFi" name="STA association" ssid="mySSID" ssid_id…
  • iView reporting very different values than UTM

    I've been looking at my iView SSL VPN reports lately and the values it's showing are drastically different for those in my weekly executive report. In all cases, the UTM is reporting much high values but they are not all off my the same factor. Some are…
  • SMTP Relay / SMTP Proxy Problem

    Guten Abend, ich betreibe seit einer Woche mein privates Projekt auf einem Rootserver: - Proxmox HV + Proxmox Firewall + IPTables mit öffentlicher IP -> iptables geben alle Ports ordnungsgemäß an die UTM weiter und funktionieren. -- Subnet 192.168…
  • Sophos UTM: best practice for uplink balancing and multipath rules

    Note: Please contact Sophos Professional Services if you require direct assistance with your specific environment. Table of Contents Oviewview Basic setup Internal network uses a specific WAN link for outbound traffic WAN interface serves…
  • Web Filtering Blocking All Connections

    Hi. i have Installed my UTM 9 with bridge Mode. however when Web Filtering is ON, all the client cannot connect to Internet. then when it's disabled all the client can connect to Internet. I don't know what cause of this. can anyone help?? i do have…
  • Sophos SSL VPN - Verbindung unter Win10 per CLI oder Powershell herstellen

    Hallo Habe eine Sophos UTM Version 9.7 ... Sophos VPN Client ist lokal installiert ... das Hertstellen von dem RemotePC (Win10) der SSL VPN-Verbindung über die GUI klappt prima ... Nun möchte ich die Verbindung per Script über CLI herstellen ... bin…
  • 20MHz und/oder 80Mhz Band in Wireless Protection auf Ap100c aktivieren

    Hallo zusammen, im Bereich "Sophos Wireless" im Thread " AP100c >>> "SSH could not reach the selected AP" diskutiert und auch schon Hilfe von eienm Sophos Technician hier aus dem Forum erhalten. Ein Forum User meinte, ich soll mein Problem - da es…
  • SMTP relay blacklist function

    Hello Community, I had a question of understanding. we see a massive brute force SMTP connections on the external interfaces. So we try to block these brute force networks and hosts from SMTP service and use the function Relaying -> "Host/Network…
  • Export and Import Config of UTM

    Hello dear SOPHOS community! We have two UTM firewall clusters. Both are the same - same firmware and same hardware (SG310). Now we would like to export the whole configuration of one cluster, e.g. Network definitions, Nat rules, WAP rules etc, and…
  • DNS best practice

    DNS Best Practice You might have seen the model we use as I've described it in many places here: The 'Global' tab of 'Network Services >> DNS' lists "Internal (Network)" (also other internal networks, like "DMZ (Network)" and any "VPN Pool" if applicable…
  • SSLVPN - OpenVPN Client nicht kompatibel mit Windows 10 2004

    Guten Morgen, der OpenVPN Client der mit der Sophos UTM ausgeliefert wird hat ein Problem mit Windows 10 2004. Das Setup installiert nicht immer den VPN Adapter. Wählt man die Installation dann manuell (per INF Datei) an, funktioniert das VPN. Aber…
  • Web Filter Policy for User / Group Not Working

    Device: Sophos UTM9 running firmware 9.510-5 Issue: When I switch on the Web Filter and configure the Base Policy everything works as it should. I can access the sites I need and block the sites I don’t need. However, when I create a new policy that…
  • No DNS resolution over (Open)VPN of Synology NAS in a Windows Server 2016 (DNS, DHCP, DC) and Sophos UTM environment

    Hello guys, I have a DNS resolution issue: The NAS has a VPN-Connection with the Sophos UTM and I can access it via my Windows Server using the IP giving from the VPN-Pool (10.242.2.X). The problem is that I want to use a FQDN name like NAS.domain…
  • WAF Error Page Customization

    As a new feature in Sophos UTM/SG 9.6 the Webserver Protection (WAF) allows to customize the web pages users see when a page is blocked or intercepted by the WAF. You can create themes for every type of error page individually or for more than one…
  • dose it possible to use a dedicated line for (GSSMO and SMTP) Upload only?

    Hello I'm using Sophos UTM SG210 with Two ADSL Lines (Slow Uploads) , that make sending emails take very long time, and i plan to add a 3rd 4G line (very fast Upload, but Limit Quota), the two ADSL Line interface work in Load balancing, are…
  • UTM Home - Set up with existing Cable modem and WLAN router

    Hi there, i seek advice on how to set up an UTM behind an existing Archer C7 WLAN router, that is connected to the WAN of an existing cable modem (no special functions like wlan, just providing internet and connected with an ethernet cable to the WLAN…
  • UTM 9.6 Public Beta Start

    Hi Community, Today we started the UTM 9.6 Beta. We created an own Beta Forum at: https://community.sophos.com/products/unified-threat-management/unified-threat-management-beta/sophos-utm-9-6-beta/f/sophos-utm-9-6-public-beta for news, bug fix information…
  • Welcome to the UTM 9.6 Beta

    Hi UTM Community! Welcome to the UTM 9.6 Beta. We are excited to announce the availability of our next UTM beta and look forward to your feedback on this release! What's new in UTM 9.6? Let's Encrypt Integration Generate and renew Let's…
  • Access UTM from FQDN

    I have a domain and would love to be able to access my UTM from that domain as a subdomain. Something like firewall.mikesdomain.com. How would I go about doing this and what ports would I need to open up? I can already access my webadmin and the user…
  • Advisory: UTM Site-to-Site Amazon VPC drops BGP neighbor after upgrading to 9.508

    Hi All, We discovered an issue where Site-to-site with AWS using the Amazon VPC connector drops BGP neighbor after upgrading to 9.508 lately. The same has been fixed, please refer the article UTM Site-to-Site Amazon VPC drops BGP neighbor after upgrading…
  • IPv6 Best Practice

    Hi, I'm running several Sophos UTM's at different places. Some in business environments, one at home with the home use license. When configuring DNS I used these two guides and that worked Pretty well. https://community.sophos.com/kb/en-us/120283…
  • How to publish two mail servers each with it's own public IP

    Hi, We need to publish a new mail server for a new domain, but we want to publish it with it's own public ip. The story :) We have Sophos UTM to manage mail protection for our principal domain, let say example.com The public ip for the UTM is…
  • WebAdmin password rest fails

    Hello, i have reset my webadmin password trough the bootloader change but after i set a new password i still cant log back in, what is hapening here. i want te get back in my firewall and router. have reset is 3 tines and rebooted the firewall…
  • Bring VLANS from our Datacenter to the Remote-Office (Red 15w)

    Is it possible to do the following: We have got a lab-environment in our datacenter. We installed a Sophos UTM and defined multiple VLANS which are attached to the VMs on our Hyper-V-Host. In our remote-office is a Sophos RED15W, connected via RED-Connection…