• Where are all the places in XG firewall to install Go Daddy SSL certificate for Exchange email server?

    Sean Rome
    Sean Rome
    Greetings everyone! This is my first time installing a renewed SSL certificate for our email server in our new XGS firewall. Where are all the places the new certificate needs to go? I've uploaded it in certificates. Applied it in email general…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Single SSL VPN profile for multiple sites

    Matt Dickens
    Matt Dickens
    Good Afternoon, We have recently performed a migration from Sophos UTM to Sophos XGS and I am currently working on re-instating the SSL VPN service for use by our third party support companies. We operate two DCs with services either 'homed' in a specific…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Resolving "Not secure" error while browsing secure sites

    Vivek Jagad
    Vivek Jagad
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Overview This Recommended Read provides you with a quick solution…
    • over 2 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: SSL VPN – Certificate Verification Failed

    Arkita Thakkar
    Arkita Thakkar
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Note: Make sure your Sophos Firewall time is correct to avoid potential…
    • over 2 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: Purging expired certs from Sophos Firewall

    emmosophos
    emmosophos
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Hello Community, Thank you to Rico for his contribution. This…
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: Install a Free and Valid SSL Certificate

    emmosophos
    emmosophos
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Note: Make sure your Sophos Firewall time is correct to avoid potential…
    • over 2 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: Installation of Multiple Certificates via PowerShell

    Bhaumik Gohel
    Bhaumik Gohel
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. ______________________________________________________________________________________________________________________________________…
    • over 2 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: Certificate Renewals with WAF and Cloudflare

    Barend Botes1
    Barend Botes1
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. ______________________________________________________________________________________________________________________________________…
    • over 3 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: Uninstall the SSL CA certificate

    Dennis Huagan
    Dennis Huagan
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Untrusting & Uninstalling…
    • over 3 years ago
    • Sophos Firewall
    • Recommended Reads
  • In XG firewall where are all the places you install a renewed SSL certificate for an email server?

    Sean Rome
    Sean Rome
    Greetings everyone, In XG firewall, I need to install and configure a renewed SSL certificate from Go Daddy. We have an Exchange server on premise. I've uploaded it into certificates. Applied it in firewall HTTPS OWA SMTP rule. Applied it in email…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • The user opens the outlook prompt certificate alarm

    Hongbo Xia
    Hongbo Xia
    Our customer recently updated the windows system patch. After the update, open the Outlook client, and always pop up a certificate warning. As shown in the figure below, please help analyze the cause of this problem, whether it is related to XG Firewall…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG: Configure SSL Remote access client to site

    Marco Malatesta1
    Marco Malatesta1
    Hello, do you know if is possible to use a third party wildcard certificate to configure an SSL remote access on an XG firewall? Thank you in advance, Marco.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Automate replacement of Letsencrypt SSL on Sophos SFOS?

    jang430
    jang430
    I am currently using SFOS 19.5.1 MR-1-Build278. I am hosting Emby (similar to Plex, I used Plex as it is more popular) container on my Qnap NAS, being protected by WAF. I have my own domain name from Porkbun, and I was able to generate SSL (Letsencrypt…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG CA and latest macOS break web sites

    rfcat_vk
    rfcat_vk
    Hi foks, I am running v19.5.1 on the XG and macOS13.3 on the mac book pro and mc air. A couple of sites no longer work and the default is https even though I enter hrttp.If I use a hotspot the issue is not observed. I have a mac mini in which the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • expired Root CA "DigiCert SHA2 Secure Server CA"

    LHerzog
    LHerzog
    Noticed some issues today with some popular SSL sites (linkedin, live, . These issues existed for some days but no one complained. The traffic was scanned by TLS/DPI engine and the servers had certificates issued by "DigiCert SHA2 Secure Server CA"…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • HTTPS decryption: Some users cannot browse site: Certificate expired yesterday

    LHerzog
    LHerzog
    We're having a strange situation again after it happened last week already on our SFOS 19.0.1 XG430: Some users browse to a website that has no exceptions on our firewall for decryption. The browser (firefox or chrome) show an error that the site…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Uploaded Certificate in Sophos XG Firewall Showing Not trusted

    Sacombank Cambodia itsupport_sc
    Sacombank Cambodia itsupport_sc
    I uploaded the certificate in every format (.pem,.pfx,.Cer) but none of showing trusted and always showing RED (X) in trusted for certificate issued from Digicert website. Please assist me to fix on this issue at earliest. Please find the attached screenshot…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Your connection is not Private

    tstan
    tstan
    Hi, purchased an XGS2100 to replace our SG230 for our Public WiFi connection. The device is not on a domain and has its own internet connection. It is only used for members of the public to get access to the internet on their own personal devices…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SSL-VPN switch from TCP to UDP

    Thomas Linnepe
    Thomas Linnepe
    Hi folks, we are currently in the rollout of SSL-VPN Configurations and noticed performance issues at users which are using LTE Internet connections with latency. So we want to improve performance by switching from tcp to udp at the sophos firewall…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to bypass SSL/TLS in SOPHOS XG

    Ahmad
    Ahmad
    hi, i have XG430 , created a firewall rule and selected with following web filtering checks: Block QUIC protocol Scan HTTP and Decrypted HTTPS Scan FTP for Malware Decrypt HTTP during web proxy filtering. SSL and TLS inspection is enabled when user…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Remote Access VPN - IPSEC with Certificate - connection export .scx file invalid - SFOS 19.5

    philbert
    philbert
    Remote Access VPN IPSEC with Authentication type certificate does still lead to invalid connection .scx file on SFOS 19.5.0 GA-Build197, SFOS 19.5.1 MR-1-Build278 and SFOS 19.5.2 MR-2-Build624 if the "Organization name" in the Certificate does contain…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Invalid Certificate

    Kharl Levinn laniton
    Kharl Levinn laniton
    I have been using SG135 UTM for 5 years and I decided to upgrade to XGS136. Just like in the UTM, I want the web admin certificate to be valid. I have made a locally signed self-certificate, installed and trusted but I'm still having issues above. I have…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 19.5.0 GA ....Can only download TLS/SSL ApplianceCertificate as .PEM format, not CER, DER or pkcs#12

    alan weir
    alan weir
    Using XG 19.5.0 GA. I can only download the ApplianceCertificate as a *PEM. file. I am certain it was letting me choose the other formats once before. Now the only file format it allows to download is default.pem and appliancecertificate.pem which cannot…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Outlook 365 security alert (Sophos SSL CA) certificate

    Mohammed Alobaidi
    Mohammed Alobaidi
    Hi all, We are receiving this security alert on Outlook 365, since ever we installed the Sophos XGS136 firewall. Please guide me to solve this issue. Thanks,
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Purge SSL Certs from cache using Frontend

    P M1
    P M1
    Continuing on the discussion below: community.sophos.com/.../507230 Is there an easy way to do this from front end? This has become a common occurrence now, with the latest incident involving Google's certs. The given workaround requires usage…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
<>