Browse By Tags

  • Blocked Website

    Hello, currently I have a problem with my sophos XGS Firewall. I would like to allow a specific Website for our marketing department. tiktok.com I also add this site to "Allowed URLs for Default Policy" and "Local TLS exclusion list" but nothing happened…
  • Mails not more delivered (MTA-Mode). After service smtpd:restart mails successfully delivered, but also very old from February/March/April

    Hi there, we had a very interesting problem with our Sophos-Firewall and the mailflow on Wednesday. On 2024-06-26 around 08:00am (UTC+2) no more mails were delivered via our Firewall. All mails were visible in the GUI under "Mail logs", but only…
  • WAF Status-Code 413 - ModSecurity: Request body no files data length...

    Hallo alle zusammen, ich habe seit einiger Zeit Probleme mit meiner XG210 und dem Versand von E-Mails bei mobilen Endgeräten. Im einzelnen geht es darum das wir E-Mails über mobile Endgeräte (Android, Apple) Empfangen und Versenden können aber sobald…
  • Email Rejected, using Protect - Email in XGS

    Hello, in the last few days I have noticed that certain emails are not being delivered, and I observed in the Sophos XGS 126 smtp_mail.log that the emails are being rejected. The senders and recipients exist and are known. This issue started occurring…
  • Versand von E-Mails mit SOPHOS XGS126 über Mail-Transfer-Agent (MTA). Fehler: all hosts for have been failing for a long time (and retry time not reached) (fast alle in China)

    Hallo zusammen, wir haben nach einem Wechsel der SOPHOS UTM auf XGS126, folgende Schwierigkeiten bei ca. 5 Lieferanten (fast alle aus China). Wenn eine E-Mail an die betreffenden Lieferanten geschickt wird, geht die in ca. 50% der Fälle durch (ohne…
  • SMTP Quarantine: cannot delete items via web console due to invalid characters

    We received an E-Mail addressed to \"?info\"@domain.de and can not delete this entry from the list of quarantined E-Mails via Web-Console. Is it possible to delete this entry using a ssh-session / command prompt?
  • How to protect Exchange OWA from brute force if the server is behind DNAT?

    Hello, need help for configurate Sophos XGS to protect Exchange OWA from brute force. S erver is behind DNAT
  • An error has occurred in resolving the URL, please update the URL and retry the policy test.

    Greetings community. I have an XGS126 device (SFOS 20.0.0 GA-Build222) I'm trying to do a policy test on google.com, facebook.com, and I get this message: An error has occurred in resolving the URL, please update the URL and retry the policy…
  • FILT-APP Block Office365 SOPHOS XGS

    Hello, I have recently see my officesetup.exe installation blocked when I activated the app-filter based on this policy "Block generally unwanted apps" on my LAN TO WAN firewall rule. This blocked was manifest juste after launch the officesetup.exe…
  • PDF gefiltert obwohl in white list markiert - Identische Bestellungen gingen zu anderem Zeitpunkt schon durch

    Hallo, wir haben unsere XGS2100 noch relativ neu und nach einigen Monaten ist es soweit, dass sie meist das tut, was wir von ihr wollen. Jetzt aber folgendes: Ab und zu werden pdf Dateien vom MIME gefiltert. In anderen Fällen kommen diese aber wie gewünscht…
  • email bounced (failing for a long time(and retry time out not reached))

    hi i have XGS4300 (SFOS 19.5.4 MR-4-Build71), it is MTA mode, today i start getting bounced email while sending email to few domain R=default_mx_router T=remote_smtp: all host for 'mahagenco.in' have been failing for a long time(and retry time out not…
  • Which RBL is flagging the email?

    XGS2300, 19.5.4 We're getting a lot of false positive blocked IP addresses lately. Where in the logs can I find what specific IP address is being blocked (since the message does not arrive I can't look at the headers) and which RBL is blocking it. All…
  • WAF non-standard ports: 503 Service Unavailable

    Hi, I have set up a new Web server protection rule following this guide. Everything works fine using port 80, but when I change the port to 1001, I get 503 Service Unavailable: Web server : IIS (Windows 11). Binding: Type: HTTP, IP address: all…
  • TLS Inspection | OCSP / CRL | Not blocking websites with revoked certificates

    Hi everyone, I'm enforcing my TLS inspection rules to more strict and secure with best practices. So my Decryption Profile: Using https://badssl.com/ for tests scenarios I had success in almost all practices: invalid date working as…
  • captive portal without login

    Is there any way to implement a captive portal without any account or guest login? Just a disclaimer -> confirm -> web surfing allowed?
  • Webfilter debian deb repositories "Malware 'Unscannable"

    We're having some strange issues currently only reported for debian repositories. When trying to download random files from there with browser or wget - the requests randomly seem to time out and / or users get a STOP message from the firewall. Sometimes…
  • Wifi Connected ICON shows offline

    Dear Team can anyone tell us which Web policy blocks or enabled the identification of wifi connected icon in the taskbar. We have to implement tight restriction in our environment due to the fact of education institution. But enabling the policy now…
  • WAF RULE NOT WORKING AND GIVING WEB SERVER 403 FORBIDDEN ERROR

    WAF rule not working for a website that hosted on internal IP in windows server 2012
  • Website Problem

    Hi, One of our users is continuously facing a problem with a website. After logging in to the website and using it for a little time, it starts showing "Wrong requested URL!" Page couldn't be found!. He tried using different browsers but same. Is…
  • Block search words in XGS2100 not working

    Dear all, For some reason the search block policy is not working. Attaching screenshots from categories, policies and firewall rule.
  • Authentication template variables for ip address

    With reference to below doc https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/WebServer/AuthenticationTemplates/index.html Is there any variable available to get client ip address? Example "client_ip…
  • Mail and issues with ActiveSync / ActiveSync 1MB File Limit

    Hello, we have also this problem and cannot send larger emails from mobile phones throuth our XG135 firewall. (ActiveSync) What are the steps to fix this problem? (1MB Limit) Thank you
  • Freigabe einzelner Webseite (Unterseite) und nicht gesamter Domain

    Hallo, ich suche in unserer XGS2300 ( SFOS 20.0.0 GA-Build222) die Möglichkeit, eine einzelne Webseite (Artikel oder zum Beispiel YouTube Video) von der Richtlinienprüfung auszunehmen. Wir haben bei uns den Webzugriff auf diverse Seiten über URL…
  • WAF funktioniert nicht mehr, Syntax error on line 98 of /cfs/waf/reverseproxy.conf

    Seit zwei Tagen erscheinen keine Einträge mehr im WAF Log auf der Browseroberfläche. Es wurde nichts an der Firewall geändert. Durch einen Hinweis in diesem Thread WAF not starting after reboot due to config error habe ich nun die Protection Policy deaktiviert…
  • Sophos Firewall: Blocking Download by File Size

    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Configuration Web Policies…