• WAF non-standard ports: 503 Service Unavailable

    woter324
    woter324
    Hi, I have set up a new Web server protection rule following this guide. Everything works fine using port 80, but when I change the port to 1001, I get 503 Service Unavailable: Web server : IIS (Windows 11). Binding: Type: HTTP, IP address: all…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • UTM 9 WAF Outlook Anywhere login failed

    Olli-204
    Olli-204
    Hi there, I’ve configured WAF for an Exchange Server 2019 according to this guide: https://www.frankysweb.de/sophos-utm-9-4-waf-und-exchange-2016-ohne-rpcoverhttp/ OWA and ActiveSync works fine but I have trouble getting Outlook Anywhere working…
    • 6 months ago
    • UTM Firewall
    • Web Server Security
  • protection Policy for the NextCloud

    AAMAA
    AAMAA
    Hello, We have a protection Policy for the NextCloud on Sophos, unfortunetly we have many issues with uploading Photo (many times the upload not working at all what ever is the Photo size or extantion ), every time we must connct to SSH to check the…
    • 6 months ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • WAF RULE NOT WORKING AND GIVING WEB SERVER 403 FORBIDDEN ERROR

    SARVESH KUMAR
    SARVESH KUMAR
    WAF rule not working for a website that hosted on internal IP in windows server 2012
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Authentication template variables for ip address

    Akshay Hegde
    Akshay Hegde
    With reference to below doc https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/WebServer/AuthenticationTemplates/index.html Is there any variable available to get client ip address? Example "client_ip…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Mail and issues with ActiveSync / ActiveSync 1MB File Limit

    m4Viper
    m4Viper
    Hello, we have also this problem and cannot send larger emails from mobile phones throuth our XG135 firewall. (ActiveSync) What are the steps to fix this problem? (1MB Limit) Thank you
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • WAF funktioniert nicht mehr, Syntax error on line 98 of /cfs/waf/reverseproxy.conf

    cougarman
    cougarman
    Seit zwei Tagen erscheinen keine Einträge mehr im WAF Log auf der Browseroberfläche. Es wurde nichts an der Firewall geändert. Durch einen Hinweis in diesem Thread WAF not starting after reboot due to config error habe ich nun die Protection Policy deaktiviert…
    • 6 months ago
    • Sophos Firewall
    • German Forum
  • Let's Encrypt renewal no longer works with Country Blocking

    Jeff x
    Jeff x
    I received the following email, this morning: The Terms of Service for Let's Encrypt have changed. Please go to WebAdmin to review and accept the new Terms of Service, otherwise you won't be able to create and renew Let's Encrypt certificates. …
    • Answered
    • 6 months ago
    • UTM Firewall
    • General Discussion
  • Sophos Firewall - WAF response 403 Forbidden for Internal requests

    R Beatrix
    R Beatrix
    Hello Sophos Community, We are migrating from a UTM 9 unit to a new Sophos Firewall unit and I've setup a WAF rule for two internal web servers. When setting up the firewall rule, I chose the Action dropdown option of "Protect with web server protection…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • New to Sophos - Allow traffic to multiple docker containers sub domains

    Eric Vanatta
    Eric Vanatta
    Hi all, I'm looking for a bit of hand holding and guidance here. What I am trying to do is allow access to internal containers hosting multiple websites and applications. I have a fresh Sophos Setup with no special custom rules or anything yet. I have…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • WAF for multiple ports

    Stuart James
    Stuart James
    Gday Needed to forward 25 ports to a webserver using WAF. I can't for the life of me work out how to enter in more than one port to either. Surely I don't need to create 25 webserver and 25 WAF rules? Anyone done this before?
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • XGS WAF Port 80 / 443

    GIT-MG
    GIT-MG
    Servus zusammen, leider ärgert mich die Webserver Protection der XGS gerade und ich finde den Fehler Partout nicht. Die Webserver sind soweit passend konfiguriert. Wenn ich die Firewall Regel (Protect with webserver protection) anlege, und dort als…
    • Answered
    • 8 months ago
    • Sophos Firewall
    • German Forum
  • WAF Rules Allowing Unexpected Requests

    cm00001
    cm00001
    Hello, I am getting some unexpected and unwanted requests (trying to find exploits) that are handled by one of the WAF Rules: Here's the WAF Rule that is being it with this traffic: Here's how it looks in the Event Viewer: How can I change the…
    • Answered
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS WAF IPV6

    admin_idl
    admin_idl
    Hello, We have the problem that users who work from home and only have an IPV6 address cannot use the WAF rules and web server access. Can we allow "any IPV6"? "any IPV4" is allowed. What would be the best approach here? Thank You!
    • Answered
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • How to Deny Direct IP access from browser ?

    Trio Fandi
    Trio Fandi
    Hi, I need advice how to Deny Direct IP access from browser. So, it only allow access by domain-name. How it done through Sophos Firewall configuration rule? I use Sophos XG 310, SFOS v20.0 Thanks
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • IP allowlist for WAF

    Electronic Repair & Logistics IT department
    Electronic Repair & Logistics IT department
    Using Web Server Protection, I want a web server to only be reachable from some IP lists or IP host groups. How can I achieve this? In Access permission , Allowed client networks , it seems that I can only choose individual IP hosts of networks. Am…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Block traffic to WAF correctly

    AquaNerd
    AquaNerd
    I'm struggling to block access to the WAF, I am trying to block all but Cloudflare IP ranges from accessing the WAF however there is still traffic hitting the WAF from non cloudflare IP's. If you are a non cloudflare IP then you get a forbidden page instead…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Port 80 and 443 open from external if using external IP address. Support says it goes to first rule that matches the port and ignores host name???

    AllanD
    AllanD
    We just had a PCI compliance scan and we failed because HTST wasn't enabled. Looking through everything HTST is enabled on all of our Web Server Protection rules including the default one. The PCI scanning company said the server replying is using apache…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Replacing expired certificate

    Jaroslav Faldik
    Jaroslav Faldik
    Is there a simple way to replace an expired certificate without having to manually replace it with a valid one in all WAF rules and other places where it is used?
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • WAF Exceptions not applying

    Stuart James
    Stuart James
    I'm getting an error on a URL with WAF for Static URL Hardening. I've added an exception but still getting the same error. What am I missing?
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Web Server Protection stopped working

    ChriZathens
    ChriZathens
    Hello guys! I have a home server running a few services on port 80 and 2-3 other ports I also have dyndns (3 hostnames) and have been using waf to connect to those 3 services without the need to enter a port in the url (There are also a couple of…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Seting up webserver protection with https -> http

    Geir Otto Olsen
    Geir Otto Olsen
    Hi, I would like to setup a Webserver protection using the WebServer and HTTPS to the Sophos FW, but behind the Firewal, I want to use HTTP. Could anyone tell me how to setup that? I can see how to setup for HTTPS, but I am not sure how to send it using…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • WAF wkth https not working

    Nazir Heravi
    Nazir Heravi
    Hallo everyone, I am facing with an issue in sophos XG with web server protection. I have created a WAF rule and redirect my alias ip to my webserver through HTTPS 443 select my certificate *company.com and add my webserver host my company.com but…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • WAF SSL Certificate Problem

    Nazir Ahmad Heravi
    Nazir Ahmad Heravi
    Dear All, I am facing with a Problem in sophos xg web server Protection, I have created all needed ruls and upload the ssl certificat to xg but in web application rule under the Host server when I select the HTTPS in the dropdaown menu I dont see me…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Exchange Enhanced Protection with SSL WAF

    gdmacmillan
    gdmacmillan
    So i know this topic has been discussed before but no one puts in a complete answer so going to ask it again. After enabling Exchang enhanced protection OWA externall breaks. I know this is due to the SSL offloading as this is mentioned in several posts…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
<>