• Adding SSL/TLS Scanning Exclusions through script

    Krystian Flemming
    Krystian Flemming
    Hello everyone, I've been attempting to write a script to add (and also remove if needed) SSL/TLS scanning exclusions in Sophos Central. From what i've gathered, it's the following PATCH request that needs to be sent: Endpoint API | Sophos Central APIs…
    • 11 months ago
    • Sophos Central API
    • Discussions
  • Issues accessing WebAdmin after FW upgrade to 9.718-5

    Jim Matson
    Jim Matson
    I'm running the Home License of Sophos UTM on a physical box (Protectli Vault) as well as a VM on my Synology. After I updated to 9.718-5 of the firmware, I am no longer able to access WebAdmin from my PC on either of the upgraded UTMs using either Google…
    • over 1 year ago
    • UTM Firewall
    • General Discussion
  • enable encryted email

    Peter Munster
    Peter Munster
    I would like to setup encrypted email. When enabling this I receive the following message: Before you turn on message encryption, make sure you have TLS v1.2 configured on your email gateway How do I configure TLS v1.2 on the email gateway?
    • over 4 years ago
    • Sophos Email
    • Discussions
  • Email Delivery Pending /Failures

    Ninjatech1969
    Ninjatech1969
    Hello All, We are having issues with mail delivery today. Looking at the logs in Exchange I am seeing the following entries. Anyone else having issue? Reason: [{LED=450 4.4.317 Cannot connect to remote server [Message=451 4.4.0 Socket error SocketError…
    • over 2 years ago
    • Sophos Email
    • Discussions
  • Forcing TLS, otherwise use email encryption

    olofd
    olofd
    Hi there, As per the manual, you can set that when TLS is not available the message will be encrypted. Is Sophos also checking if the certificate is valid? In the email appliance, you can separately choose both options. You can select the following…
    • Answered
    • over 5 years ago
    • Sophos Email
    • Discussions
  • Sophos Firewall: WAF and claimed weak ciphers

    KingChris
    KingChris
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Strong ciphers Weak ciphers…
    • over 4 years ago
    • Sophos Firewall
    • Recommended Reads
  • Release of Sophos Web Appliance v4.3.10.3

    RichBaldry
    RichBaldry
    We have just released version 4.3.10.3 of the Sophos Web Appliance software. Your appliance should receive this update over the coming week if it has not already upgraded. This release addresses the recently-discovered vulnerability in OpenSSL, CVE-2022…
    • over 2 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • TLS E-Mail Verbindung

    HunkIT
    HunkIT
    Hallo Wir hosten bei uns 3 verschiedene Domains. In den SMTP TLS Einstellungen haben wir ein Wildcard Zertifikat für unsere Hauptdomäne *.company.com drin. Laut dem TLS Verbindungs-Test hier "www.checktls.com/TestReceiver" funktioniert die TLS Verbundung…
    • over 2 years ago
    • UTM Firewall
    • German Forum
  • DNS hinterlegen

    Chris -
    Chris -
    Guten Abend, ich dachte, dass das eigentlich eine ganz einfache Frage ist, aber nach der Suche hier im Forum bin ich komplett verwirrt. Vielleicht kann mir jemand unter die Arme greifen: Ich möchte, dass alle Endgeräte in meinem Haushalt einen bestimmten…
    • over 2 years ago
    • UTM Firewall
    • German Forum
  • Seeing lots of TLS Handshake errors on Server 2012r2 clients

    mthi0591
    mthi0591
    Like the title says I am seeing a huge volume of SCHANNEL error events in my Server2012r2 severs that are all relating to requests to 4.sophosxl.net From what I can tell that URL is supporting a narrow string of Cipher suites for TLS 1.2 that were only…
    • over 3 years ago
    • Sophos Central
    • Discussions
  • Sophos Message Router service not starting after TLS 1.2

    Bujar Lushta2
    Bujar Lushta2
    Dear Sophos Community, I have Sophos Endpoint Protection 10.8 running on Windows 2016 and Sophos Management Console running 5.5.1 running on a separate server . I have disabled TLS version 1.0 and 1.2 on Windows 2016 server, as a result after the reboot…
    • over 3 years ago
    • On-Premise Endpoint
    • Sophos Endpoint Software
  • FTP uploads to ftp.sophos.com not longer working due to TLS1.0 Handshake failure

    LHerzog
    LHerzog
    Since this week me and my colleagues cannot upload files to ftp.sophos.com:990 over explicit TLS happens to 195.171.192.29 and 195.171.192.30 Probably caused by Sophos Servers only offering TLS 1.0 Using filezilla latest version 3.56.0 with GNUTLS…
    • Answered
    • over 3 years ago
    • Support Portal Feedback
    • Feedback and Ideas
  • Release of Sophos Web Appliance v4.3.10.2

    RichBaldry
    RichBaldry
    We recently began rollout of version 4.3.10.2 of the Sophos Web Appliance software. Your appliance should receive this update over the coming week if it has not already upgraded. This release addresses an issue that was caused by the recent expiry of…
    • over 3 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • SG430 | UTM 9.707-5 | SSL VPN | TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity) & TLS Error: TLS handshake failed

    Alexander Tarnowski
    Alexander Tarnowski
    We use a Sophos SG430 | UTM 9.707-5 for SSL VPN. It worked flawlessly for the last 9 months. Two days ago we physically moved the hardware appliance to a new server room. After we powered and booted the UTM again, everything worked fine, except the…
    • over 3 years ago
    • UTM Firewall
    • VPN: Site to Site and Remote Access
  • Logging der TLS Version ein- und ausgehender Connections

    Thomas Coenen
    Thomas Coenen
    Hallo, wir würden gerne die TLS Version für die Webserver Protection auf v1.2 anheben und möchten dafür vorher überprüfen, ob noch Verbindungen über TLS v1.0 oder TLS v1.1 aufgebaut werden. Gibt es eine Möglichkeit das über die GUI oder die CLI…
    • over 3 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • SSL3.0 TLS1.0 for Port 3400

    raywo
    raywo
    Hi, I did a vulnerability scan of my external IP and in the results I can see that SSL3.0 TLS1.1 and TLS1.1 are still supported for Port 3400. I guess this was already asked before but I didn't find it in the forum. Is there already a solution for…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • Remote Ethernet Device (RED)
  • Release of SWA v4.3.9.1 - Mac OS Catalina, iOS 13 and certificate trust changes

    RichBaldry
    RichBaldry
    We've just started the rollout of version 4.3.9.1 of the Sophos Web Appliance software. This update is a small one, aimed at ensuring compatibility with the new version of macOS, Catalina (version 10.15) and iOS 13. In Catalina, Apple have updated the…
    • SWA Regen UI Cert.png
    • View
    • Hide
    • over 5 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • Forced check on certificate chain used for required TLS negotiation for specific hosts / sender domainsTLS

    Techstuff
    Techstuff
    For secure communication with one of our customers we need to comply with the two following conditions. Is this possible on the Sophos UTM SG450? - Validate certificate ( There should be a check when sending email using TLS that there is a trust with…
    • over 6 years ago
    • UTM Firewall
    • Mail Protection: SMTP, POP3, Antispam and Antivirus
  • TLS - Outbound TLS certificate presentation

    P L
    P L
    Is it possible that outbound email messages secured by enforced TLS present the TLS certificate for verification? At the moment the certificate seems only to apply to incoming email. Incoming: 2018-06-05T14:21:11.056403+01:00 <ext mail srv> sendmail…
    • over 6 years ago
    • UTM Firewall
    • Mail Protection: SMTP, POP3, Antispam and Antivirus
  • Release of SWA v4.3.6 - Safesearch for Bing over HTTPS

    RichBaldry
    RichBaldry
    It's time for another small update for the Web Appliance. Version 4.3.6 will be going out to customers over the next couple of weeks. This version addresses a number of bugs that have been reported by customers. See the release notes for details. …
    • over 6 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • SSL certificate is not valid

    Panadero
    Panadero
    Hi All, I have had a security scan performed on the outside of our utm and one of the results displays the following message: Synopsis The remote web server uses an old version of SSL. Description The remote service accepts connections…
    • over 6 years ago
    • UTM Firewall
    • General Discussion
  • WAF - VWS - TLS version setting removed from UTM 9.506

    RBCJB
    RBCJB
    UTM 9.5 introduced the ability to set the TLS version on a per-VWS basis. This was a much needed feature that allowed us to increase the TLS version setting for Virtual Web Servers that we wanted to run a higher version, whilst allowing us to continue…
    • over 6 years ago
    • UTM Firewall
    • Web Server Security
  • RD Gateway stopped working for Win7 Clients after up2date to 9.506

    StephanG
    StephanG
    Hi there, some of our external users reported that they could not connect to our RDS Server (W2k2R2) over the RD Gateway (W2k2R2) anymore. This only affected the Win7 Users (latest patches) and started "in december". After ruling out Windows Update…
    • over 6 years ago
    • UTM Firewall
    • Web Server Security
  • TLS ROBOT Vulnerability?

    Papadug
    Papadug
    US-CERT have released an advisory about a new vulnerability in TLS which could allow an attacker to access sensitive information by obtaining the TLS pre-master secret which will allow TLS traffic to be decrypted. http://www.kb.cert.org/vuls/id/144389…
    • over 6 years ago
    • Email Appliance (Read Only)
    • Discussions
  • Release of SWA v4.3.4 - Important information for customers using HTTPS decryption

    RichBaldry
    RichBaldry
    A new version of the Sophos Web Appliance software is being rolled out starting this week. Version 4.3.4 combines a number of fixes for reported bugs, including a potential vulnerability reported to us by Christian Demko of MWR InfoSecurity. Thanks to…
    • over 7 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
>