• Report on all outbound IP traffic by source

    PeterHolland
    PeterHolland
    Hi, hopefully i'm missing something obvious (although not holding my breath on that) Background: I am looking into identifying the source and type of some unexplained outbound traffic on a network connection, essentially there are a number of…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Strange logs in /log/syslog.log file

    George F.Kapaniris
    George F.Kapaniris
    The system is producing this output below every second as it appears in the advanced shell, it seems that login process is restarting continuously. Feb 3 10:01:00 (none) daemon.info init: process '/bin/login' (pid 20205) exited. Scheduling for restart…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Network Accounting/Reporting Bandwidth/Visualization

    JeckDanniels
    JeckDanniels
    Hello fellow UTMers, is it possible to create a report that shows how utilized the external WAN interfaces are over a certain period of time in the same form as already shown in the Logging/Reporting - Network Usage section? (Not showing GB that were…
    • over 7 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Can't search Web Filtering Log UTM 9.408.4

    JSinclair
    JSinclair
    I am trying to find who visited a particular site within a short time range (half hour). I tried downloading the log for the day in question, but I am unable to extract the file. It fails with a CRC error at about 40%. I have tried downloading the file…
    • over 7 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • 2 ipsec VPN connections working but no VPN reports

    jeffmcfarlane
    jeffmcfarlane
    Hi All, XG firewall with 2 x IPSEC connections working. I can access resources either side and monitor them however there are no VPN reports on the reports page. This is also the case for active threat protection. There was an issue where the main…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Blocked entire "Unclassified Applications"

    LoveMae
    LoveMae
    Hi guys, I just wanna ask help or any suggestions how can I blocked entirely "Unclassified Applications" that eat most of my bandwidth? See reports below: Any recommendations will be much appreciated. Thank you. Regards, Anthony
    • over 7 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Network rule set not to log still showing Web browsing logs, what might be causing this?

    CMR
    CMR
    We have an HA pair of XG430s running 16.01.2 and have created a rule for public Internet access. We don't want to log every site a customer visits but despite unticking the log box it is still logging.
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • How can I log a host or number of hosts and their duration of use per day ?

    Jeff O'Connor
    Jeff O'Connor
    I have a large number of staff that we want to monitor their time spent in the office based on their mobile phones connecting to our wifi, or their PC connecting to the wifi / network. We know the mac addresses of each device, and have specified reservations…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • [Solved] Dropping packet: DNS packet of insuffient length: 25

    Mike Keller
    Mike Keller
    Hi everyone I've got an internal DNS server. LAN Network 10.99.150.0/24 UTM LAN IP 10.99.150.1 DNS Server 1 10.99.150.100 Everything is working fine, but n early every 5 seconds I've got a new log entry like this: 2016:11:03-09:19:52 vm ulogd[12400…
    • Answered
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Best methods to monitor HTTP traffic

    MikeJeffers
    MikeJeffers
    I just stood up a UTM 9 instance at my house. I've got several kids with numbers mobile devices. What's the best solution for monitoring web traffic and reporting on it? I'm interested in reporting based on user. User definitions will have to be MAC…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Feature Request :Log file format [Customize Reports view]

    mehmet sinansahin
    mehmet sinansahin
    hello; xg firewall log format is as follows: Is it possible to adjust? DATE, TIME, COMPUTER NAME, IP, MacAddress, HOST, URL
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • No Reports menu when in Bridged Mode

    AnthonyB
    AnthonyB
    I am running a XG 85W in bridged mode but the Reports menu is no longer available. I have Network and Web Filtering subscriptions enabled and confirmed they are active. Can I confirm that bridged mode excludes any traffic or security reports functions…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • Comprehensive Customer reports?

    TimFoster
    TimFoster
    I was referenced to the Executive report and it does provide some good information for us. However, when exporting the report it becomes this convoluted mess. The information is there but I do not think the average person would understand. Is…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • Is Kiwi Syslog service manager compatible?

    domTon
    domTon
    I've configured the firewall to report to a syslog server but nothing comes through. I've tried disabling the firewall on the desktop/server and still nothing is reported from the Sophos firewall. I've also use the servers built in test message to verify…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • Canned Reporting?

    TimFoster
    TimFoster
    HI, I am looking for any documentation about setting up canned reports on the Sophos Firewalls. We are currently evaluating the XG Firewalls and reporting is the main reason we are looking into these devices. I have searched the knowledge…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • System Log for Hung Process / Crashing?

    DanielFriedhoff
    DanielFriedhoff
    My Sophos box ran great for a little over a month, but over the last five weeks, it's continually locking up. I turn the monitor on and find the console frozen, and have to power cycle the box. The machine I'm using (Dell OptiPlex) has built-in diagnostics…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Missing? info on HA failover

    apijnappels
    apijnappels
    This morning we had an HA failover where the slave became master. What I noticed after the failover is that logging (graphs) were not available in the period before the failover. This evening I let the previous master become master again and now I can…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Kerberos not working for ONE user. How can I fix "Key table entry not found"?

    Someone7272
    Someone7272
    function="adir_auth_process_negotiate" file="auth_adir.c" line="1600" message="gss_accept_sec_context: Key table entry not found" This problem has been badly affecting one machine resulting in "Authentication failed" messages every time a user logged…
    • over 8 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • HTTP/S Malware blocked 47 . Where can I find in logs info about this?

    adriansuperstar
    adriansuperstar
    Hello Community! HTTP/S Malware blocked 47 . Where can I find in logs info about this? If it is a virus blocked I will go to Logging and reporting - Web Protection - Virus Downloaders and see all about it but in malware i cannot find anything even in…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Suggestions to get AlienVault or OSSIM to work with Sophos UTM

    jlbrown
    jlbrown
    Has anyone successfully got Sophos UTM working with AlienVault? (or OSSIM). Ie set up Remote Logging to AlienVault. Any tips has to how to do it? Does the built-in AlienVault plugin for Sophos UTM work? Doesn't seem to for me, but I'm new to AlienVault…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Enable Logging for OFFICE Internet Use , so can monitor the Internet Activity of the Domain User

    sanjayyadav
    sanjayyadav
    Hey Guys, I have faced a issue in my Company , One Domain user has made some not permitted Activity on the Internet and we need to find out, who was the one ? Like the IP of the computer , which accessed the Internet website at that particular time…
    • over 8 years ago
    • UTM Firewall
    • Web Protection: Web Filtering & Application Visibility/Control
  • live monitoring of ping traffic

    MarkFerrel
    MarkFerrel
    I'm coming from a Cisco ASA background and am finding the monitoring/logging on the UTM to be a bit difficult. On the ASA I could look a the syslog and see live monitoring of ALL traffic. Then filter accordingly. The specific thing I'm looking for now…
    • Answered
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Rubbish logging

    PaulRoberts
    PaulRoberts
    Sorry but I am struggling a bit with logging, either I am doing something wrong or it's just rubbish. I have defined an explicit policy rule to drop all outbound traffic coming from a single IP address, I know it works because the client goes off-line…
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • RE: Site no longer appears in Logging and Reporting-->Webserver Protection-->Details tab after firmware upgrade.

    AlbertoSoresina
    AlbertoSoresina
    Hi everyone, this is my version: Firmware version: 9.402-7 Pattern version: 101124 And now the LOGGING &REPORTING - WEBSERVER PROTECTION in empty, by 2 days. Very strange, the SG310 in new and resatarded.…
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
  • Site no longer appears in Logging and Reporting-->Webserver Protection-->Details tab after firmware upgrade.

    JBooks
    JBooks
    One of our websites is no longer appearing in the Logging and Reporting-->Webserver Protection-->Details tab after upgrading the firmware to 9.401-11 from the previous version. I can see traffic to that site in both the Live Log and the WAF log, but not…
    • Answered
    • over 8 years ago
    • UTM Firewall
    • Management, Networking, Logging and Reporting
<>