• XG 136 mit SFOS 20.0.0 hinter einem Exposed Host. Ich bekomme kein DNAT hin

    ChristofS
    ChristofS
    Hallo Gemeinde, bis jetzt hatte ich immer einer SG230 in dieser Konstallation. Diese habe ich nun gegen eine XG136 getauscht und die Firmware SFOS 20.0.0 GA-Build222 ist installiert und die Konfiguration so von der SG230 übernommen Die Reds und…
    • 5 months ago
    • Sophos Firewall
    • German Forum
  • Proxy inbound connection to external ip

    LMSIIATO
    LMSIIATO
    Good morning, I currently have a server in an on-premise datacenter that responds to TCP port 12233. So there is a very normal DNAT on the XGS firewall of the public ip 80.80.80.80:12233 towards the private server ip 192.168.1.10:12233 This service is…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Server access : port to port won't work

    helmut willems
    helmut willems
    hello , i'll try a simple port forwarding when i setup this like below , it works when i change the source port to 7887 then it dont forward. why o why ?
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • XG125 v20.0.1 - Portweiterleitung und Zugriff auf Interne Hosts nach Update nicht mehr möglich

    Michael Nährig
    Michael Nährig
    Hallo Zusammen, unglücklicherweise wurde ein Update der XG125 von 19.5. auf 20.0 durchgeführt und anschließend war die gesamte Konfiguration zurückgesetzt. Nachdem ich nun die meisten Einstellungen mühsam wieder eingerichtet habe, scheint mir entweder…
    • 5 months ago
    • Sophos Firewall
    • German Forum
  • Allgemeine Frage zu Diensten und Regel Freigabe für Telekom pbx 2.0 Telefonie

    derinder85
    derinder85
    Hallo Zusammen, ich beschäftige mich neu mit der XGS 107 und betreibe diese aktuell neu im eigenen Netzwerk. Aufbau: Fritzbox --> XGS 107 --> Netzwerk Jetzt komme ich schon zur ersten Herausforderung. Zusätzlich hätte ich noch allgemeine Fragen…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • German Forum
  • Different default WAN gateways for different VLAN groups

    Administrator User484
    Administrator User484
    Hello. I wonder if Sophos Firewall could be set up to have each VLAN having different WAN gateways ? For example, VLAN 1 will go to WAN 1 and VLAN 2 will go to WAN 2, so that there will virtually be two networks. Originally, I was thinking to set…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Converting iptables to NAT rule

    woter324
    woter324
    Hi, I have been given an iptables command and I would like to create the same rule on my XG. Could anyone confirm if I have "translated" the rule correctly, please? iptables -t nat -I PREROUTING -s 10.100.20.19 -d www.riscocloud.com -p tcp --dport…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Access to the local subnet from the WAN interface (NAT RULE?)

    Matteo Frati
    Matteo Frati
    Hello everyone! I have 2 SOPHOS firewalls in two different buildings, connected by Long Range Aerials (point to point). FIREWALL 1 is configured like this: LAN 192.168.122.X (Aerial 1 is part of this DHCP pool) WAN public IPs (static) then…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Firewall rules and policy

    Charlie Dodd
    Charlie Dodd
    Hi, I am wanting to block the IOT network (xxx.xxx.5.xx/24) from pinging the default gateway of other networks so created a firewall rule to do so however when testing, devices in the IOT network are still able to ping the default gateway of other networks…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • How to create a network object / host / rule which allows access to WAN but not LAN (RFC RFC 1918)

    Matjaz Lorber
    Matjaz Lorber
    Hi! I am a proud owner of XGS 107 and pretty happy with it. I am running a homelab with a few vlans, really nothing special. But there is something, that is bothering me: I am also using Barracuda Firewalls where i work, and there i really like the…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • protection Policy for the NextCloud

    AAMAA
    AAMAA
    Hello, We have a protection Policy for the NextCloud on Sophos, unfortunetly we have many issues with uploading Photo (many times the upload not working at all what ever is the Photo size or extantion ), every time we must connct to SSH to check the…
    • 6 months ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • DAHUA CCTV NOT STREAMING ON DMSS APP ON REMOTE PHONE

    TimothyWanume
    TimothyWanume
    After installing Sophos XGS2300, our client stopped viewing his Dahua CCTV remotely on his smartphone, the NVR is online in the AP but CCTV footage is not I dstreaming. I did all the necessary port foward and ports are open RTSP: 554 TCP: 37777 HTTP…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Firewall policy unable to deploy to some customers: Host \{hostname}\ could not be updated

    Alex Simpson1
    Alex Simpson1
    Hi guys, We have been deploying a firewall policy for a few months now and have noticed that there are a few customer firewalls that are unable to deploy the configuration. They all appear to be getting a similar error to the one pictured below. Can…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Wifi Router internet goes down if a AD user tries to access internet via a WIFI router whose IP address is added to the Firewall rule allowed list

    Muhammad Safdar
    Muhammad Safdar
    Hi Sophos community, I'm having a issue for my Wireless router. I have created two rules: 1. Rule 1 for AD users to WAN In the above rule internet is allowed once user is authenticated via AD. Everything is working fine. 2. Rule 2 for Wifi router…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Connection between two different subnets

    Qbitter
    Qbitter
    Hi community, I'm trying to connect two different Subnets. This is the environment: Subnet A 192.168.1.0 /24 Gateway: 192.168.1.1 Port 4: Company with DHCP address 192.168.1.55 Device: FritzBox Subnet B 10.0.100.0 /24 Gateway 10.0.100.1 Port…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • PHYSICAL NETWORK INTERLINKING BETWEEN 2 XGS DEVICES

    TimothyWanume
    TimothyWanume
    Hello guys Fiber Interlink Network 1 should be able to communicate to network 2 through the fiber link Please assist in configuring
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • How to block youtube for a particular IP range in Sophos XG

    Ruka
    Ruka
    Hi everyone, Firstly let me explain the setup i have for my home network Have WAN plugged into a mini PC which runs Sophos XG. On Interface 4 of Mini PC i have plugged in ubiquiti AP from which other devices get wifi connection ( mobile phone , laptop…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Need to Allow trafic from specific AS Number

    Trio Fandi
    Trio Fandi
    Hi, I read this forum discussion (10 months ago) and it was said that this will be a new feature request. Has it available right now ? xg / xgs - allow ip from specific asn number only Thanks.
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • How can I block QUIC without.......

    JohnMMM
    JohnMMM
    Can anyone please tell me (A) How to block all QUIC traffic in and out ,and (B) will that then give me better log reports of url's visited ?. Thanks
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Sekundäre Netze bei WatchGard - Alias bei Sophos

    Sven Gerhardt1
    Sven Gerhardt1
    Hallo zusammen, ich bin sehr gerne jemand, der Sophos benutzt. Früher UTM nun XG. Wir sind von WatchGuard gerade umgestiegen und nutzen nun eine XGS2100. Soweit sind wir auch zufrieden, nur die alten Sekundären Netze sind ein Problem. Wir haben…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • German Forum
  • Cant get a simple directly connected network firewall rule working. XGS126

    PeteH
    PeteH
    I am completely stumped by this. I am sure its something obvious that I am overlooking. Lan Port 1 - 192.168.1.254/24 MGMT port 5 - 172.16.0.254/24 I already had a rule saying mgmt subnet source 172.16.0.0 could access lan subnet destination 192…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Any/Any rule still showing Violation in packet capture

    Ben Woolley
    Ben Woolley
    What did I do wrong?
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Update (patch) DMZ linux Server

    Sofos network
    Sofos network
    Hi I have a linux server in the DMZ, and I want to manually patch it from time to time. so I want to open access only during patches then close access to WAN. what are all the rules to put in place. well I'm going to choose the scheduled time tab.
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Two site URLs, 1 public IP, PAT to test server on 443

    Ian McGuinness
    Ian McGuinness
    Port forwarding rule I have an external ip address (PortB:8) currently used for a production website on port 443. I would like to be able to access a test web server via the same public IP via port 65443 and translate to port 443 at the server.…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Forwarding non-standard ssh port to standard ssh port internal (remote SFTP Server)

    Sofos network
    Sofos network
    Hi all, # XG330 I have a project to set up an SFTP server to transfer data securely from a remote station to the SFTP server located in the DMZ.(Head Ofice) the server is installed, configured and integrated into the dmz. the remote client uses an…
    • 7 months ago
    • Sophos Firewall
    • Discussions
<>