• SafeGuard on Mac SSL Verification and SSL certs in keychain

    EricWoelfel
    EricWoelfel
    From my understanding, when you update a certificate for SSL communication on the SafeGuard Management Center then you have to update it on each of the MAC clients. We get our certificates from an official authority (not self-signed) but they are only…
    • Answered
    • over 6 years ago
    • Encryption
    • Discussions
  • Certificate could not be updated as it is already used by HTTP Based Policy

    Julius Perkins
    Julius Perkins
    One of my certificates expired that's in use in several places. When I go to edit the certificate and upload the new, it fails with the following error at the top center of the screen: Certificate could not be updated as it is already used by HTTP…
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • #7779325 - SSL Certificates for User Portal

    Desmond Besa
    Desmond Besa
    Hi All, Hope all of you are doing well. I am just trying to secure my user portal by assigning a url and applying a SSL Wildcard Certificate on the Sophos XG 330. I was able to convert the PFX and private key that the RAPID SSL gave me and applied…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Is it possible to adjust the SSL VPN configuration within the Sophos XG Firewall?

    Ronald Buys
    Ronald Buys
    Dear All, I am looking for the possibility to adjust the SSL VPN configuration on the Sophos XG Firewall. I do know it is possible to adjust it on the local machine (for instance Windows). It this something already in-place or is this something…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • SSL VPN not working

    EricNilsson
    EricNilsson
    Hi! I can't get my SSL-VPN to work, I followed Sophos own guide for setting this up, only changing the port. See below for settings. The log outputs the following: 2017:11:10-14:47:05 openvpn[25581]: TCP connection established with [AF_INET…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • VPN: Site to Site and Remote Access
  • Inbound SSL Decryption

    Steve Shaw
    Steve Shaw
    I guess Sophos UTM can do inbound SSL decryption, not able to find in the configuration guide. Can some one please advice how to configure this. Thanks, Steve
    • over 7 years ago
    • UTM Firewall
    • General Discussion
  • Sophos XG home Web GUI access - SSL/certificate issues under OS X 10.13

    Patric Beuthen
    Patric Beuthen
    Dear All I recently upgraded my MacBooks to OS X 10.13. Since I do not connect to my XG every day (or even week), I am not absolutely sure, if the issues at hand are related to OS X 10.13. Safari now reports: This connection is not private The Sophos_CA_…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • 8094/tcp open on WAN port reveals SF-OS

    Mokaz
    Mokaz
    Hi there, Just been nmap'in the WAN port of an XG, with pretty much the default configuration and no DNAT/SNAT or any services in the protected zone opened at all. The scan reveals the port 8094/tcp and further reveals that the service SSL certificate…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • IPS alerts - Have I to be concerned?

    FormerMember
    FormerMember
    Hi, since I am using XG, I'am getting always IPS alerts, and I am concerned about, because I don't know the reason of these alerts. Are IPS alerts a alert about accessing websites with vulnerabilities or outdated software, or means an IPS alert…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • iDrive Backup

    kyushu2002
    kyushu2002
    How does one best set up firewall rules for iDrive backup solution? Problem: A network I am working on uses iDrive backup solution. iDrive connections are prevents when using the XG Firewall inline. I've likely narrowed down the issue to when "Prevent…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Question on SSL cert renewal for Mac clients

    AWilson
    AWilson
    I assume I have to install the SSL cert (new, purchased, not self signed) into IIS (duh) and presumably into the keychains into system on the Mac OS client. I don't really recall this from my Architect so apologies if this has been covered. Does anyone…
    • Answered
    • over 7 years ago
    • Encryption
    • Discussions
  • SSL-VPN: Authentication fails with OTP because prefetching doesn't consider case sensitivity any more -> BUG?

    JanboNörskau
    JanboNörskau
    Hi Guys We recognized an anomaly after updating the UTM to 9.412-2 from 9.405-5 (I don't know when this came up - at least in 9.412-2): SSL-VPN usage with AD-Group auth + OTP auth. -> Worked fine for 150 users in the past. Now: Users created and…
    • over 7 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • XG Firewall Default CA

    Edwin Jewell
    Edwin Jewell
    I am having issues which consist of an inability to save SSL VPN settings (They always revert to default) and downloading the SSL client for windows. After doing some research it seems my Default CA may be the issue, and when I check the Default CA it…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • [Workaround] Quarantine Digest Email IP instead of hostname

    Information Systems1
    Information Systems1
    The Quarantine Digest Email settings only let you select an IP address based on Port/Alias, instead of allowing you to specify a hostname. This causes a certificate error when clicking the "My Account" or "Release" links in the email. The admin console…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • RED 50 Dropping Connection

    Mark Moore1
    Mark Moore1
    Hello, This has been going on for a little over a month now and seems to be getting worse. We have a RED 50 connected to our UTM 220 and following recent firmware upgrades (I think) it has become unstable. I see lots of other similar cases out there…
    • over 7 years ago
    • UTM Firewall
    • Remote Ethernet Device (RED)
  • XG Best Practice, Firewall, IPS, VPN ect.

    AnthonyChallis
    AnthonyChallis
    Hi All, We have a new XG + Sophos central/interceptX. I have the firewall setup with a copy of LAN-WAN IPS with all but windows clients/servers removed, SSL decrypt+scan and yellow or above heartbeat policy setup. Is this how we should go or does…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • SSL vpn with activedirectory and full upn

    mjpmotw
    mjpmotw
    We are using the regular SSL VPN client for our home office users. The users can use their regular windows username and password to use the SSL VPN because we are syncing some groups to the backend. Since we are using full UPN as c norris@roundhouse…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • New CA certificates ...

    dirkkotte
    dirkkotte
    Hi, Thawte create a new CA. now i get a "B" within SSL-Server-test. Problem message is "This server's certificate chain is incomplete. Grade capped to B. " Must i import the new CA certificate only or the SUB-CA certificate too.
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Web Server Security
  • SMC behind apache reverse proxy with lets encrypt certificates

    ThomasKriener
    ThomasKriener
    Hello, we are currently using SMC with a StartSSL-Certificate which is expiring soon, so we need to have an alternative. One option would be to put SMC behind a apache reverse proxy which is using lets encrypt certificates. The exchange of the certificate…
    • over 7 years ago
    • Sophos Mobile
    • Discussions
  • SSL Client won't install on windows 10

    Gil Gross
    Gil Gross
    I just install a new (my first) Sophos XG. Installed on Azure using market place image. After setup I configured SSL-VPN client and clientless. I logged into the site and downloaded the client and configuration for windows. However when I try…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Website Protection and External SSL Certs

    MichaelSomerville
    MichaelSomerville
    Hello Sophos Community; I have spent the better part of a day trying to find a definitive guide/answer on the use of External SSL Certificates from Commercial CA's when you have 1 or more internal web servers running HTTPS behind an XG, and no luck…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Sophos SSL VPN and SSL Scanning

    Pedulla
    Pedulla
    I'm sitting behind a UTM 9.4 firewall(1) with HTTPS Decrypt and scan enabled. I'm trying to SSL VPN into another UTM 9.4 firewall(2) using a publicly addressable FQDN via OpenVPN on a Linux Mint 18.3 laptop. Firewall1 will not allow the SSL VPN to…
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • SNI Support

    Timothy Stewart
    Timothy Stewart
    Is SNI supported by XG Firewall? I have multiple SSL certs for multiple domains and one IP and I would like to be able to route traffic to virtual web servers based on this host name inspection. Web servers like Apache, nginx, and IIS as well as every…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • IPS Inspection of SSL traffic

    Greg G
    Greg G
    After looking through the UTM 9 features it looks like Web Filtering and Web Application Firewall offer a SSL inspection. It's my (potentially flawed) understanding that WAF and Web Filtering do not equal IPS. Is IPS blind to SSL traffic or is there…
    • over 7 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • SSL Certificate error Outlook 2013

    Hans PetterJacobsen
    Hans PetterJacobsen
    We are starting to get Certificate alerts in outlook for users that are accessing office 365 or google calendar directly i Outlook 2016/2013. Under Web Protection - Web Filtering - HTTPS we have URL filtering only marked. Any suggestions on how to…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
<>