• Unable to download Self-Signed CA certificate for SSL VPN Sophos Connect

    Werner Smit
    Werner Smit
    Good Day, I am trying to download our Self-Signed Certificate from the Firewall to deploy to all users to prevent users from seeing a certificate error when signing on to the Sophos Connect SSL VPN. There is no download button on the firewall what…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sectigo Certificate Status Not Trusted

    Trio Fandi
    Trio Fandi
    I have import both Certificate and Root CA in Certificate Authorities Menu. But Certificate status Not Trusted persist. I saw a weird description in subject of certificate appears in Sophos. There is a different description between Certificate Menu…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos - Certificate authority: Invalid or not installed

    André Besteiro
    André Besteiro
    Good afternoon, When we accessed Sophos through the browser, we got an insecure certificate alert. We imported a new certificate into Sophos (the same used on our website), but the following message appears in the certificates menu: Certificate…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • HTTPS Decryption Stopped Working - 19.5.2

    ptho
    ptho
    Hi Sophos Community, We've had it reported to us by those that use the monitoring software that https decryption has stopped working. We aren't exactly sure when it stopped working, but it appeared to have done some time after moving to 19.5. Though…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Model:SFV1C4 - how to import a certificate for my remote access VPN?

    Geir Otto Olsen
    Geir Otto Olsen
    I have tried to go to Certificate, and import it there, but it is not Trusted. . Certificate authority: Invalid or not installed Issuer /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA What…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • 500 error when Importing TLS certs using the API

    Elliana Perry
    Elliana Perry
    I am investigating importing our TLS certificates using the SFOS API but running into an error that I am struggling to understand. The request XML: <? xml version "1.0" encoding "UTF-8" ?> < Request APIVersion "1905.1" > <!-- API Authentication…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Webserver Protection - Zertifikat ist nicht auswählbar

    KarstenFL
    KarstenFL
    Moin, ich muss mich zum ersten Mal mit der Webserver Protection auseinandersetzen. Dabei habe ich das Problem, dass ich beim Anlegen einer neuer Firewall Regel, das Zertifikat nicht auswählen kann. Was habe ich bisher gemacht? 1. Das Zertifikat…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Url filtering in guest wifi

    Danilo Dani
    Danilo Dani
    Good morning, i installed sophos firewall to use it as wifi guest access, through the hotspot feature. I also bought the standard subscription, so with web Protection the possibility of doing url filtering. I then loaded the CA of my public domain, to…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Add Windows Server Self-Sign Cert as trusted?

    Quallensaft
    Quallensaft
    What is the way to whitelist and add a self-sign cert (Windows Server) on the firewall? Of course I can import the certificate under certificates but its is still not valid (red cross). e.g. Exchange server is using a self-cert for SMTP SSL/TLS connection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sectigo RSA Domain Validation Secure Server CA removed?

    Quallensaft
    Quallensaft
    Hallo, any reason why the (build-in) CA cert from Sectigo RSA Domain Validation Secure Server CA was removed the last days? Is that normal or a bug, pattern updates? Anyone else has this CA on the firewall? Had to add it again manual by hand to work again…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Bug: downloading webproxy CA results in admin logout

    LHerzog
    LHerzog
    Hi, when downloading the Proxy CA here: this logs you out of webadmin immediately. SFOS 19.5.2 MR-2-Build624 XG and XGS
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • HTTPS scanning certificate authority (CA) cert from settings not in use

    Quallensaft
    Quallensaft
    - Web -> HTTPS decryption and scanning -> HTTPS scanning certificate authority (CA) -> "Default" cert in settings - Profiles -> Decryption profiles -> Block insecure SSL -> "Default" cert in booth Re-sign settings - what is in use -> "SecurityAppliance_SSL_CA…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Query validity period of the installed certificates on SFOS

    Steppenwolf
    Steppenwolf
    Hej together, does anyone know a way to monitor the installed certificates on the Sophos Firewall. Especially the expiration date would be interesting. I have not found a way via SNMP, SYSLOG or API. I would like to query this from our central monitoring…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ssl ceritificate error

    satyabrata bastia
    satyabrata bastia
    Hi, we are using sophos-xg-210,self generated Certificate used but in monitoring its showing no secure protocol available so please help us to find out where is issue.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Neues Zertifikat kann nicht ausgewählt werden

    Reto Lang
    Reto Lang
    Ich habe mein Zertifikat erneuert und das neue Zertifikat auf der Firewall eingespielt. Dieses wird auch mit einem grünen Haken als Trusted gekennzeichnet. Jedoch kann ich das Zertifikat in "Admin and User Settings" nicht auswählen. Auch in der Firewall…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • XG public trusted cert problem in webfilter from different lan zone than primary internal

    nd
    nd
    Hello community, I have switched from UTM to XG and now I have the following problem with pubic trusted certificates in other zones than the default internal zone. I have configured and uploaded the certificate successfully in the XG appliance,…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • strongswan / ipsec - Certificate chain with 3 certificates does not work. X.509 Certificate Chain Files

    Peter Reiter
    Peter Reiter
    Hello to all, I would like to set up an L2TP remote access VPN connection with authentication via certificate. Unfortunately, this does not work if an intermediate certificate is used without having to modify the ipsec configuration via shell. Environment…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: SSL/TLS Inspection on Mobile Devices

    Raphael Alganes
    Raphael Alganes
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview What is TLS/SSL Inspection…
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
  • "The operation will take time to complete.." when adding new certificates

    Pedro Calvo
    Pedro Calvo
    Good day to you all When I add a new certificate or certificate authority, always get the next message: "The operation will take time to complete. The status can be viewed from the Log viewer page" New certificates never appear. I found nothig…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall RMA. How can reconnect RED device

    Luc_GLLM
    Luc_GLLM
    Hi, I have a defective XGS2100, an RMA has been opened and a new product will be sent back to me. When it arrives I will do a configuration restore starting from the backup of the faulty one, but two questions arise: 1) I have 5 RED20 devices connected…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web Admin Zertifikat funktioniert nicht.

    Christopher Ocak
    Christopher Ocak
    Hallo Leute, ich betreibe aktuell eine Sophos XGS 87 mit Standard Protection. Firmwarestand: SFOS 19.5.1 MR-1-Build278 Ich habe folgendes Problem... Mich stört schon seit einer Ewigkeit die Zertifikatsanfrage beim Aufschalten auf die Webadmin…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • XGS googleadservices.com

    Firewall-Tom
    Firewall-Tom
    Hallo Zusammen, googleadservices.com wird scheintbar out-of-the-box von einer XGS als Advertisements erkannt: Die o.g. Meldung ist erst lesbar wenn man das XGS CA Zertifikat importiert hat. Eine Web>Exception hilft nicht: microapp-discovery…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • XGS Certifikates: Certificate authority: Invalid or not installed

    encar
    encar
    Hello, I want to replace an SG firewall with an XGS. I donwloaded the wildcard certificate (.pem) and the certificate of the CA from the SG and uploaded them on the XGS. Though the the wildcard certicicate doesn't trust the CA. How can i solve this…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Enabling HTTPS on Enterprise Applications

    Srikrishna Pothukuchi
    Srikrishna Pothukuchi
    Hi, We have one VMWare server protected by this Sophos firewall. All our enterprise web applications are hosted on this server. Now, after accessing these enterprise applications, even though they are passing through the firewall, we are getting…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Comodo Certificates

    Mark Smith7
    Mark Smith7
    Hi I cant find anything recent on this in the forums. Im looking to purchase a wildcard certificate for securing several things. Are there any issues i need to be aware of using either a comodo positivessl (cheaper) or essentialssl? I would…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
<>