• Converting iptables to NAT rule

    woter324
    woter324
    Hi, I have been given an iptables command and I would like to create the same rule on my XG. Could anyone confirm if I have "translated" the rule correctly, please? iptables -t nat -I PREROUTING -s 10.100.20.19 -d www.riscocloud.com -p tcp --dport…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Access to the local subnet from the WAN interface (NAT RULE?)

    Matteo Frati
    Matteo Frati
    Hello everyone! I have 2 SOPHOS firewalls in two different buildings, connected by Long Range Aerials (point to point). FIREWALL 1 is configured like this: LAN 192.168.122.X (Aerial 1 is part of this DHCP pool) WAN public IPs (static) then…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Firewall rules and policy

    Charlie Dodd
    Charlie Dodd
    Hi, I am wanting to block the IOT network (xxx.xxx.5.xx/24) from pinging the default gateway of other networks so created a firewall rule to do so however when testing, devices in the IOT network are still able to ping the default gateway of other networks…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to create a network object / host / rule which allows access to WAN but not LAN (RFC RFC 1918)

    Matjaz Lorber
    Matjaz Lorber
    Hi! I am a proud owner of XGS 107 and pretty happy with it. I am running a homelab with a few vlans, really nothing special. But there is something, that is bothering me: I am also using Barracuda Firewalls where i work, and there i really like the…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • DAHUA CCTV NOT STREAMING ON DMSS APP ON REMOTE PHONE

    TimothyWanume
    TimothyWanume
    After installing Sophos XGS2300, our client stopped viewing his Dahua CCTV remotely on his smartphone, the NVR is online in the AP but CCTV footage is not I dstreaming. I did all the necessary port foward and ports are open RTSP: 554 TCP: 37777 HTTP…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Firewall policy unable to deploy to some customers: Host \{hostname}\ could not be updated

    Alex Simpson1
    Alex Simpson1
    Hi guys, We have been deploying a firewall policy for a few months now and have noticed that there are a few customer firewalls that are unable to deploy the configuration. They all appear to be getting a similar error to the one pictured below. Can…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Connection between two different subnets

    Qbitter
    Qbitter
    Hi community, I'm trying to connect two different Subnets. This is the environment: Subnet A 192.168.1.0 /24 Gateway: 192.168.1.1 Port 4: Company with DHCP address 192.168.1.55 Device: FritzBox Subnet B 10.0.100.0 /24 Gateway 10.0.100.1 Port…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to block youtube for a particular IP range in Sophos XG

    Ruka
    Ruka
    Hi everyone, Firstly let me explain the setup i have for my home network Have WAN plugged into a mini PC which runs Sophos XG. On Interface 4 of Mini PC i have plugged in ubiquiti AP from which other devices get wifi connection ( mobile phone , laptop…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Need to Allow trafic from specific AS Number

    Trio Fandi
    Trio Fandi
    Hi, I read this forum discussion (10 months ago) and it was said that this will be a new feature request. Has it available right now ? xg / xgs - allow ip from specific asn number only Thanks.
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How can I block QUIC without.......

    JohnMMM
    JohnMMM
    Can anyone please tell me (A) How to block all QUIC traffic in and out ,and (B) will that then give me better log reports of url's visited ?. Thanks
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Cant get a simple directly connected network firewall rule working. XGS126

    PeteH
    PeteH
    I am completely stumped by this. I am sure its something obvious that I am overlooking. Lan Port 1 - 192.168.1.254/24 MGMT port 5 - 172.16.0.254/24 I already had a rule saying mgmt subnet source 172.16.0.0 could access lan subnet destination 192…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Any/Any rule still showing Violation in packet capture

    Ben Woolley
    Ben Woolley
    What did I do wrong?
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Update (patch) DMZ linux Server

    Sofos network
    Sofos network
    Hi I have a linux server in the DMZ, and I want to manually patch it from time to time. so I want to open access only during patches then close access to WAN. what are all the rules to put in place. well I'm going to choose the scheduled time tab.
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Two site URLs, 1 public IP, PAT to test server on 443

    Ian McGuinness
    Ian McGuinness
    Port forwarding rule I have an external ip address (PortB:8) currently used for a production website on port 443. I would like to be able to access a test web server via the same public IP via port 65443 and translate to port 443 at the server.…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Forwarding non-standard ssh port to standard ssh port internal (remote SFTP Server)

    Sofos network
    Sofos network
    Hi all, # XG330 I have a project to set up an SFTP server to transfer data securely from a remote station to the SFTP server located in the DMZ.(Head Ofice) the server is installed, configured and integrated into the dmz. the remote client uses an…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • 1 ISP WAN, 18 ISP LAN addresses - how to I setup a port for an edge router to go out ISP LAN IP

    avett1058
    avett1058
    We have 1 WAN IP from our ISP 18 LAN IPs from the ISP Current setup is one CAT6 from ISP to Sophos Firewall. Firewall has the 1 WAN IP interface setup for internet We need a port enabled for on the firewall for a Vendor router to use one of the…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • How do i link a NAT rule to a firewall rule?

    Tomas Z
    Tomas Z
    I created a new rule which allows traffic originating from VPN subnet to the external IP address. I verified in the logs that the traffic passes by unobstructed. Also verified in SSL VPN settings that the particular VPN profile contains that IP address…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Zugriff auf zweite Netzwerkzone

    RalphZ
    RalphZ
    Hallo, kann mir jemand helfen, denn ich bekomme es nicht hin. Ich habe auf einer Sophos XG ein Netzwerk 192.168.101.xx auf Port1 und ein Netzwerk 192.168.102.xx auf Port 5 eingerichtet. Jetzt möchte ich vom Netzwerk auf Port1 auf das Netzwerk von Port5…
    • 7 months ago
    • Sophos Firewall
    • German Forum
  • Statische Route und Firewall Regeln

    Aphrodite
    Aphrodite
    Hallo zusammen, ich habe eine Frage bzgl. der Statischen Routen. Ich möchte eine SG auf eine XGs migrieren und möchte Dienst für Dienst umziehen. Ich möchte in diesem Zuge mit Statischen Routen arbeiten. Nun stellt sich mir die Frage, wenn ich auf der…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • German Forum
  • Switch and AP6 URL Allow List for XGS Firewall

    Eli
    Eli
    Hello Sophos Team, is there a Documentation on what URLs / IPs need to be in a Firewall Rule for Destination Host? I know the Ports that are needed: HTTPS / NTP / DNS -> Forwarded to Firewall IP and Uplink to DNS Protection Just found a List for…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Firewall Rule Doesn´t Work Сorrectly

    Alex K
    Alex K
    Good afternoon I work at Virtual Box. I have three virtual machines. The first is the Sophos firewall, the second is the Windows 10 client. And on the third I have an Ubuntu server. The task is to block traffic from the Windows 10 client to the Ubunu…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Port 113

    midnightSun
    midnightSun
    Sooo when scanning the system i've noticed 113 is the only port showing as closed / reject. Since the other ports are Drop I've created a rule to drop 113 from all connections but SFOS isn't honoring the rule. Why? Why would they decided to reject only…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Ports blocking on LAN zone.

    Alex KABWE
    Alex KABWE
    Hello dear all, I'm connected with one of my clients via LAN, without going to the internet, just a LAN to LAN connection to have access to their server. But the port open to receive SNMP traffic is blocked from time to time, and I no longer receive…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • XGS126 and Blink Cameras

    Michael Witmer
    Michael Witmer
    Setting up Blink Cameras and the XGS126 is blocking communication with the Blink Servers. Have updated the policy to allow 554, 443 and 80 for the camera's IP Group but still no go. Anyone else got this to work ??
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Internet stop every day on same time on Sophos XG135

    Tihomir Trifonov
    Tihomir Trifonov
    Hello, we have a problem with our client where we put Sophos XG135 with latest update 20.0.0 on their network, like every day at the same time somewhere around 12:30-1pm and in the evening around 7-8pm, the internet stops but Sophos continues to work…
    • 7 months ago
    • Sophos Firewall
    • Discussions
<>