• WAF and Logging

    Memorycard
    Memorycard
    Hello everyone, I have some questions and hope you can help: 1. We are publishing some web servers behind the firewall using WAF. There are some "Forbidden" messages and checking the Reverseproxy.log shows OWASP ModSecurity. As we can see only a simple…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Root Certificate automatically included by WAF of Sophos Firewall?

    Markus Quirmbach
    Markus Quirmbach
    Hi everyone! We are using a Sophos XGS2300 (SFOS 19.0.1 MR-1). We uploaded a pfx-certificate to the WAF which specifically included only the webserver certificate itself and its intermediate certificate. But, when we check the site with a tool like…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAF - Request Entity Too Large

    SteveChung
    SteveChung
    Hello, I am running with Sophos XG210 (SFOS 19.0.1 MR-1-Build365) . There is Request Entity Too Large error is still existing when I download file larger than 1 MB from WAF protected website. Here's the error message. ========================…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAF no longer working after backup XG and then restore to XGS

    Michael Großmann
    Michael Großmann
    Good morning community, I have a problem with WAF after a migration from XG230 to XGS2300. It was a XG230 HA cluster which I disbanded before the backup and only backed up one firewall. I imported this backup into a new XGS2300 and again formed a…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Two web servers on one ip public - question about DNAT

    Marco Alunni Pini1
    Marco Alunni Pini1
    I've got 2 web servers on different local IP. Both IIS. (x.x.x.7 and x.x.x.21) I've done 2 waf rules on firewall but i've got a DNAT on HTTP direct connect to 1 server (x.x.x.7) It is necessary have DNAT rules (loopback and reflexive also)? Infact…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Step By Step Guide to publish RDS Web and RDS Gateway usiing WAF rules

    Patrick Loman
    Patrick Loman
    Hello everybody, Is there anyone who has a step by step guide on making RDS Web and Gateway work using WAF rules. I have been trying to get this to work for more than a day now and I can't get it to work. My setup for now is RD Sessionhost, RDWeb…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAF - how to protect a public server

    Balocco SpA - Ufficio IT
    Balocco SpA - Ufficio IT
    Hi, we have a web server with a public IP. Let's say the IP is 123.123.10.1/28. The gateway of this server is a network interface of Sophos XG, lets say 123.123.10.14/28 (we are autonomous system, we have several public IPs). How can I protect the web…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAF

    Lev Anni
    Lev Anni
    Hi, I'm trying to use Web Application Firewall to protect web servers behind NAT. Currently I have configured firewall to accept HTTP traffic and forward it to internal server. So my question is, in case of WAF, is NAT required to exist or it's automatically…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • False Positive which can't be skipped?

    Ale_V2
    Ale_V2
    Hello everyone I have deployed the Firewall for quite some time now. Recently I noticed problems whilst uploading Files to my Synology NAS which sits behind a WAF. After some short research I found that everytime certain Files are tried to upload the…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Minecraft Server hinter Web Server Protection

    timbo036
    timbo036
    Grüßt euch zusammen, vorab zu meinem Setup: Meine Sophos UTM läuft auf einem Terra Mini Rechner in der aktuellsten Version. Die ist mit der WAN Schnittstelle an eine FritzBox angeschlossen und hat dort eine feste IP aus dem FritzBox Netz. Wenn ein…
    • over 2 years ago
    • UTM Firewall
    • German Forum
  • Does Web server protection (WAF) support HTTP/2?

    James WBush
    James WBush
    Hi On a Sophos XG with "Web server protection," we host a website (WAF). Now that http/2 is available, our contractor wants to make adjustments to our website. He inquired about the WAF's support for http/2 and whether that was OK. Only the fact…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • WAF - Web Server protection and HSTS

    SOMOA
    SOMOA
    Hi I have a new ADFS 2019 system behind a WAF on XG. The external tests keep telling me it has Strict Transport Security (HSTS) off. Is there a setting on the XG that affects this when putting a local server behind the WAF or have I missed something…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: WAF and claimed weak ciphers

    KingChris
    KingChris
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Strong ciphers Weak ciphers…
    • over 4 years ago
    • Sophos Firewall
    • Recommended Reads
  • Does Web server protection (WAF) support HTTP/2

    rexer
    rexer
    Hi We're hosting a Website behind the "Web server protection" (WAF) on a Sophos XG. Now our contrator is planning to update our website to use http/2. He asked if that is ok and whether the WAF support http/2. I only found information about Sophos…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Protection Policies - "Save" Button not Working

    John Groller
    John Groller
    Hello all. I'm trying to add a new "Protection Policy". When I fill in everything and press "Save"... nothing happens. I think the "Save" button goes from a dark blue to a lighter blue, but nothing saves, no messages, no refreshes, nothing. No feedback…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Webserver Protection Exchange Cluster

    AlexanderPoettinger
    AlexanderPoettinger
    Hello, I'm having some trouble wit the webserver protection for an Exchange 2016 Cluster. We're running a brand new XGS3300 firewall cluster in our datacenter with 10 Gig internet connection. I've configured only IPS rules for the Exchange Webserver…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XG: Cannot change WAF Certificate

    Patrick Wolfensberger
    Patrick Wolfensberger
    Hi there Last week, my wildcard certificate expired. No biggie. Got a new one, imported it into the firewall, everything ok. When I selected the new certificate in my WAF rules, I was able to save this configuration and expected the firewall to use…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Redirection

    Memorycard
    Memorycard
    Hello everyone, is Sophos WAF okay with redirecting http://wwww:aaa to https://wwww:aaa ? It seems to be okay with default http and https ports, but not working with non-default ports
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XG & Exchange 2019 - WAF not working - URL hardening

    Sophos User2126
    Sophos User2126
    Hi, I'am lokking for some help to come over a problem with Exchange 2019 and WAF with static URL hardening. I use this poular documentation here: https://www.frankysweb.de/sophos-xg-18-webserver-protection-und-exchange-2019/ and it did not work as…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: How to configure WAF over an IPsec Site-to-Site

    Shweta
    Shweta
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview What to do Related information…
    • over 4 years ago
    • Sophos Firewall
    • Recommended Reads
  • access https

    Mohamed Khandouch
    Mohamed Khandouch
    hi i have two server using https mail server and web server when i want to access from outside to the sever web it load always the mail server, and when i change port to 80 it work but i want to use https for web server. pls any help i have sophos…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • General WAF understanding

    njabi
    njabi
    Hi guys I have a general and maybe basic WAF / reverse proxy question: I do use some ressources from WAN-side by setting up a "simple" Firewall and DNAT rule to port-forward these ressources. Clients that match the firewall rule have access by calling…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Web Server Protection (WAF) with certificate based authentication

    rexer
    rexer
    Hello We're trying to use a Webserver behind web server protection (Sophos XG) where clients have to authenticate themself with a certificate. We're able to reach the Website and we can authenticate with username and Password. But, however, our clients…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Can't See the WAF Works

    Onur Kaya
    Onur Kaya
    I configured the WAF protection for my apache2 server, but when i use waf tools to test it, it doesn't seem like works and I don't see any logs except from 127.0.0.1, did i missconfigured it?
    • over 2 years ago
    • UTM Firewall
    • General Discussion
  • Website protection

    juan k debb
    juan k debb
    Hi, my website got some serious attacks from different locations. Can I secure my website with Sophos Firewall? My site url is https://www.autoreinigung-noack.de/ . Any help will be appreciated
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
<>