Browse By Tags

  • Sophos Central: Provide Wildcard Config Example for Sophos XG Firewalls Web Filter Exceptions

    Please provide Wildcard Config Example for your own Firewall Product, like Sophos XG. Don't let customer puzzle to try to get the Config right. https://docs.sophos.com/central/customer/help/en-us/PeopleAndDevices/ProtectDevices/DomainsPorts/index…
  • Not useful - https://support.sophos.com/support/s/article/KB-000046133?language=en_US

    I raised 1 issue related Sophos Connect 2.3 version & you added some KBA below link. https://support.sophos.com/support/s/article/KB-000046133?language=en_US Above KBA link is not useful because if we will follow KBA step then we will have to…
  • Data management

    See Data management: Log retention report period: Specifies how long the report data is kept. Changes to the settings come into effect at 00:00. <- should likely say raw data or log data instead or report data if I understand the function correctly. The…
  • Install the Sophos Connect client through GPO

    The script proposed in the documentation "Install the Sophos Connect client through GPO" (url: Install the Sophos Connect client through GPO - Sophos Firewall ) it's incorrect. The script to avoid reinstalling Sophos Connect checks for the existence of…
  • [QueryCorner][October2023] Reviewing NSA and CISA Top 10 Misconfigurations

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Background 1) Default Configurations…
  • Step by step go through all necessary steps

    I now have a .pro file but no idea how to utilize it, you can more pedagogically explain each step and how to make use of the .pro file.
  • My guide will be better

    Hi, I have just confiuged HA as a networking layman an I think my guide will be better....just saying. I will post it via support once I have it in final draft
  • SOPHOS XG DHCP BOOT FILE PXE/SCCM

    Hello everyone . I have a problem with the configuration of the PXE/SCCM taking the XG as DHCP . Here is my config - next server: ip address of my TFTP server (SCCM&***; - Boot file location: SMSBootPM100003\x64\wdsnbp.com I get this error ( TFTP time…
  • XGS: UTQ customization

    Not all businesses follow the same web restrictions. Our business is expected to visit sites with Alcohol - yet, we cannot customize the UTQ to indicate Alcohol (& Tobacco) are acceptable. UTQ still reports it as risky behavior. We have already set Alcohol…
  • Need ability to configure UTQ categories

    Not all businesses should consider "Alcohol & Tobacco" as risky. There are businesses, like ours, that regularly visit web resources that are categorized as such. Presently, we, and your MSP partner, are unable to customize the UTQ and we have users erroneously…
  • [QueryCorner][March2023] Deep Diving into OneNote Attacks

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Index Purpose Prerequisites Query #1 - Live Discover - Check…
  • [QueryCorner][February2023] Data Lake - Sophos Firewall: Threat Hunting Dropped Logs

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Sophos Firewall uses firewall rule ID "0" in your log viewer…
  • [QueryCorner][February2023] Data Lake - Sophos Firewall: Port Scanning Detections

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Purpose Sophos Community has amassed an incredible catalog of queries…
  • The documentation items are not in line with the current SFOS and need to be modified.

    https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/FirewallManagement/Firewalls/CentralManageXG/index.html There appear to be differences overall, but the specific items pointed out are The name of the item "Sophos Central" in…
  • Add KB for Error Message "HA could not be enabled" in HA Setup

    Problem: While configure the Primary Device in HA (active-passiv) you will get the non descritive Error "HA could not be enabled" if the HA Link is not up or the Peer Device is not reachable. What To Do: - Verify HA Interface Link is UP and Peer…
  • Integrated Site Web services with company internal software

    Integrated Site Web services with company internal software Web Service URL - br.ampbr.com/.../hh Site Web Public Ip -162.11.15.15,119.14.15.12 I have a DMZ server which run application ,to which this URL is integrated by API programmer I need…
  • KB-000042455: Sophos Firewall: How to fix problems with enabling HA - Add reminder to check HA Interface Link Status

    https://support.sophos.com/support/s/article/KB-000042455 Please add the following at "What To Do" - Check HA Interface if Link Status is up after enabling HA, otherwise check Cabling (Swap RX/TX on direct fiber connection between devices)
  • OpenSSL Security update announced

    Hello Sophos, are Sophos firewalls (SG and XG) affected by the OpenSSL vulnerability? https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html Ben
  • AD Authentifizierung nicht mehr möglich

    Hallo zusammen, wir haben aktuell das Problem, dass man sich von einem Standort aus nicht mehr gegen das AD Authentifizieren kann. Macht sich zum Beispiel daran bemerkbar, dass die Adminuser nicht mehr angemeldet werden können, oder neue AD Gruppen…
  • Site-to-Site SSL VPN (UTM -- XG)

    Hallo In einem früheren Beitrag Site-to-Site SSL VPN (UTM 2 XG) - German Forum - UTM Firewall - Sophos Community wurde erwähnt dass SSL VPN nur funktioniert wenn die XG Firewall der Server ist. SW Version in diesem Beitrag waren: UTM (FW 9.705-3) und…
  • Is a limit of 50 IP addresses still realistic for home use? UTM vs XG (when will UTM be retired)?

    I found a closed, 5 year old discussion with the same subject which bares revisiting. With IPs in just about every technical device (camera's smart TVs, appliances, lighting, speakers... the list goes on and on) is 50 still feasible for Sophos UTM and…
  • Inconsistency of manual pages for Multicast routing

    On page https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Routing/StaticRouting/NetworkMulticastRouteAdd/index.html it states to "Specify the multicast IPv4 address from the following address range: 224…
  • Why did I not get the full term when I activated my license key?

    https://support.sophos.com/support/s/article/KB-000036502?language=en_US Multiple scenarios should be answered here. For example, customer you lapsed few years with device since it was being stored somewhere. Some of the vendors have policy if you…
  • HA Documentation makes no sense

    Hey! This article is totally senseless. The initial device role of the auxiliary device has to be configured as auxiliary, not as primary!
  • IPsec Site-to-Site on XG18 not working

    Hi, I installed Sophos SFOS with XG18 on my 2 SG210 Appliances, becuase we need to have more then 1 DHCP-Relay. But even with Firewall XG the IPsec Site-to-Site won´t work. I configured it for 3 VLANs like mentioned here: https://docs.sophos.com…