• How can I set up web access via PROXY PORT only?

    Someone7272
    Someone7272
    After a year, I've decided to try Sophos XG again. Currently using UTM 9.5 - which has its issues, but works well. I am trying to find out how to force all web requests through the proxy port. Sadly, I'm not getting far with Sophos XG. If I add a…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Poor detection rate of web filtering - caused by wrong categorization or stay many websites uncategorized?

    FormerMember
    FormerMember
    Hi, XG has an poor detection rate in webfiltering, e.g. when trying to open websites of denied web categories like "nudity" or trying to open malware infected pages. Is this caused by putting new websites in wrong web categories, or is this because…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Unable to forward TCP 80 or 443 - all other DNAT rules working ok

    Andrew Taylor
    Andrew Taylor
    Hello, I'm having a frustrating problem with forwarding TCP 80 & 443 to an internal server. No matter what I do the firewall just keeps dropping the connection. I've got many other DNAT rules in place which work perfectly well but anything I do with 80…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Office 365 Certificate errors - Suppliers blaming my web filtering

    Chris Stewart1
    Chris Stewart1
    I haven't been at this company long and I've never managed a Sophos UTM before but every user here is plagued by certificate errors in Outlook. We use Office 365 and Outlook 2016 and users are constantly presented with this prompt... Of course many…
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • Release of SWA v4.3.2.1 - Security fix

    RichBaldry
    RichBaldry
    Today we are publishing update version 4.3.2.1 for the Sophos Web Appliance. This is a fairly small update that covers a couple of security-related issues. The most significant change removes support for Microsoft Internet Explorer 8.0 and earlier when…
    • over 7 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • Calls to HTTPS sites falling under filter action 'warn' always open the user portal

    Andreas H
    Andreas H
    Hi all, opened a support ticket for this as well - however, as my last ticket is still open after 6 months with no reply at all I try my chances here. It's not easy to describe the issue in a single sentence as subject line but the problem I experience…
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • SFOS 16.05.4 MR-4 - HTTP Redirection Not Working

    Fernando Colon
    Fernando Colon
    HTTP redirection feature for a firewall rule is no longer working after upgrade to SFOS 16.05.4 MR-4. Any HTTP requests that match the particular rule are supposed to be automatically redirected to a HTTPS request, but that it is not happening. The HTTP…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • IPS differences between Chrome and Edge browsers

    Dean Jones
    Dean Jones
    I have IPS working and scanning HTTP and HTTPS traffic. Using the EICAR test files ( http://www.eicar.org/85-0-Download.html ) I get a blocked warning from the XG firewall on Chrome for all 8 variants of the malware test file. On the Edge browser I get…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • XG105w http error 502 bad gateway from vlan to vlan

    Viken Najarian
    Viken Najarian
    Hello, I got a weird issue with my XG105w: I have set up several VLans as follows: Vlan1: 192.168.16.0/24 Vlan10: 192.168.10.0/24 Vlan20: 172.16.16.0/24 Vlan30: 10.16.16.0 / 24 Vlan40: 10.0.0.0/24 My local servers (domain controller active…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • HTTPS traffic not getting to WAN interface

    Sol Alogaga
    Sol Alogaga
    I am new to Sophos but I am experiencing a bizarre issue. The XG firewall does not have any license for Web Proxy and it is also not using an enterprise CA certificate. There is a rule to allow traffic from internal network to a WAN interface, when…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Disable certificate authority web proxy

    Tich Matongo
    Tich Matongo
    I am running the XG firewall as a direct proxy in gateway mode and it is working correctly for HTTP traffic. The rule I created for the web proxy does not have any web filtering and the Decrypt and Scan HTTPS option is disabled. However, it gives me an…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Problem Cannot allow youtube only facebook

    Rodney Altamera
    Rodney Altamera
    Hi to All, Good day. I need an assistance regarding my setup of Sophos XG 310 Firewall. I tried to block facebook and youtube and was able to by using application blocking. The problem is I created a specific rule for allowing certain IPs from accessing…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Release of SWA v4.3.1.4 - Chrome and SSL decryption

    RichBaldry
    RichBaldry
    We have begun to roll out another SWA update - version 4.3.1.4. This update should be available to all customers within the next week. This update was made necessary by an upcoming change to Google Chrome. In version 58 of Chrome, HTTPS certificate…
    • over 7 years ago
    • Web Appliance (Read Only)
    • Release Notes & News
  • HTTPS scanning Web Protection SSL error ERR_CERT_COMMON_NAME_INVALID

    KarstenStolten
    KarstenStolten
    Hi After Google has updated Chrome, we now have problems accessing websites with SSL. HTTPS Scanning is enabled on the Sophos UTM and the problem seems to be that Chrome no longer accepts an empty DNS name in the SSL certificate presented in the browser…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • General Discussion
  • HTTPS SSL CA deployment

    Nicola S
    Nicola S
    Hi All, I've decided to give HTTPS scanning ago, however, when deploying the certificate via GPO it's intermittently working. Sometimes gets removed etc or even though it's there, the websites still giving security alert page on chrome. I'm using…
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • Can't Access HTTPS site and site with HTTP are working

    Chaitanya K
    Chaitanya K
    Hi Everyone, I have installed Web server (Linux Apache) instance in AWS and provided public access to web server through HTTP with Sophos UTM 9 and it is working fine. when I configured HTTPS for same Web server (Linux Apache) and tried to access HTTPS…
    • over 7 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Slack & SSL Decrypt

    KaipoAlakai
    KaipoAlakai
    Hello, Here are the settings I needed to use to get Slack working with SSL Decrypt: Protect > Web > Exceptions [A-Za-z0-9.-]*\.slack-msgs\.com [A-Za-z0-9.-]*\.slack-edge\.com files\.slack\.com The only box that I have checked is to disable HTTPS…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Bypass WAF for specific URL

    Gary Burch
    Gary Burch
    I have a few HTTPS sites successfully published through my UTM Firewall (mostly Exchange Admin Console/Outlook Web Access). I'm now trying to set up another application, using a different domain name, but the Web Application Firewall log is reporting…
    • over 7 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • can not connect to https website when use vpn

    AllenHuang
    AllenHuang
    sorry English poor. hope you can understand me. I have two device , A is xg85 , B is xg230 two device connect vpn I have website for service in B company , use http and https in the same ip 192.168.1.15 http://192.168.1.15 ,https://192.168.1.15…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Website Protection and External SSL Certs

    MichaelSomerville
    MichaelSomerville
    Hello Sophos Community; I have spent the better part of a day trying to find a definitive guide/answer on the use of External SSL Certificates from Commercial CA's when you have 1 or more internal web servers running HTTPS behind an XG, and no luck…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Assign new SHA256 certificate to webadmin

    sanjayyadav
    sanjayyadav
    Hello Sophos community Members, I have question regarding the ssl certificate which was assigned to the Sophos Webadmin. my Current HTTPS certificate is generated by the UTM itself and the Hash Algorithm is SHA1 which was used for the certificate. …
    • over 7 years ago
    • UTM Firewall
    • General Discussion
  • Certificate Update not possible when used in Firewall-Rules

    MarkusArndt
    MarkusArndt
    Hi, I have HTTPS-Certificates from LetsEncrypt.com for all my subdomains. I uploaded the Certificate in the XG und used them in many Firewall-WebServer-Protection-Rules. This Certificates expire after 90 days and I have a Script do renew them easily…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • HTTP / HTTPS traffic does not pass the proxy

    Lightflasher
    Lightflasher
    Hello everyone, I have the problem that traffic from two applications does not pass the proxy. The proxy runs in transparent mode without authentication. The proxy is configured for HTTP / HTTPS. The traffic is not visible in the proxy log, the traffic…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • Netflix Streaming will not work [Resolved]

    RobertBurri
    RobertBurri
    I am having issues getting Netflix streaming to work. I've read through probably every discussion on the forum, but they appear old and none have worked. Luckily Netflix is not a big percentage of what we watch, but I'm pretty sure it was working until…
    • Answered
    • over 7 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • Ubisoft Uplay Web Exceptions

    KaipoAlakai
    KaipoAlakai
    Hello, After much troubleshooting, here is what I had to unblock to get the Ubisoft Uplay desktop client to work without any issues: I had to create a HTTPS decryption exception with the following URLs local[0-9]*-mtl-[0-9]*\.ubisoft\.qc\.ca/ steamcdn…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
<>