• Web Application Firewall (reverse proxy) - pass client ip to server

    Jason Brainerd1
    Jason Brainerd1
    Right now the WAF is showing as the source ip address in the log files of my servers. I'd like to see the public ip address of the clients that are accessing the servers. I've enabled "pass host header" but that doesn't seem to do it. Is this possible…
    • over 1 year ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Web Application Firewall (reverse proxy) - block or whitelist public ip addresses

    Jason Brainerd1
    Jason Brainerd1
    I'm using the WAF as a reverse proxy. I'm wondering if there is a way to block or whitelist access by ip address? i found this post from 9 years ago saying it'd be available in 9.3 but if it's available now i'm not seeing it: RE: Source-IP filter…
    • over 1 year ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Problem with garbled site when using WAF with UTM

    Hiroshi Okuyama
    Hiroshi Okuyama
    Hello. I am using UTM version 9.7. I have configured a web server inside with UTM's WAF. But when I access the site from outside, I cannot see the site properly because of garbled characters like Arabic characters. Can someone please lend me some…
    • over 1 year ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Web Server hinter Site2Site nicht erreichbar

    Jan Esders
    Jan Esders
    Hallo zusammen, leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter. Folgende Situatiion: Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • How to config waf without domain

    cy z
    cy z
    I want to set up a WAF on the firewall, but a domain needs to be set in the WAF rules. My server does not have a corresponding domain, how should I set it? I checked the official website manual, but I don't quite understand the statement in the manual…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS webserver protection on port 8080

    Joerg Seyfried
    Joerg Seyfried
    Hi y'all, I am struggling with the following scenario: Webserver protection works fine for several sites. Now I would like to protect an internal web service that should be available via https (yes, http S ) on port 8080 (I know...). Webserver Protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF - Rule greift nicht, Verständnissproblem?

    Matthias Rieche
    Matthias Rieche
    Hallo zusammen, ich wollte mich mal mit den WAF Möglichkeiten beschäftigen. Grad das Path-Specifig Routing ist für mich interessant. Ich habe jetzt 2 VM´s in der DMZ, jeweils mit Apache2 auf Port 80 (alles Testhalber). Ich habe jetzt wie im Screenshot…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Confused rule id and broken WAF rule.

    Michal Talman CZ
    Michal Talman CZ
    Hi, I'm having trouble with the WAF, XGS 2300 v19.5.1 I add the webserver web .xxx.xxx - it has policy ID 129 . But if I go to web .xxx.xxx in the log it shows that web.xxx.xxx has policy ID 43 . I get a 503 error But the policy ID 43 is spsluzba.xxx…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • RD-gateway connection is interrupted by other WAF rule changes? How and why?

    SenorChang
    SenorChang
    Hello, I have a question regarding if this a bug, feature or just misconfiguration of our part: I've successfully managed to configure the RD gateway and RD web access in the Sophos XG with WAF rule. I took the RDG 2012 profile provided by the XG and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Using WAF to redirect a webserver root to a specific path?

    GernotMeyer
    GernotMeyer
    Hi all, I use a XGS 2300 with actual path level. We migrated fresh from UTM. In UTM we redirected in WAF to have mail.server.com redirected to mail.server.com/owa (Exchange Outlook Web Access). I only find old articles describing, that this is…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Revisit: Microsoft Teams Calendar through WAF

    Daniel Thau
    Daniel Thau
    For all searching for this Problem with Teams not showing the calender app using hybrid szenario. Refering to this basic guide: Sophos UTM: Create WAF to allow traffic through Exchange 2016 using the MS Connection Tool: https://testconnectivity…
    • over 1 year ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Web Server Protection XGS - LAB Test

    Muhammad Fahmi Zainuddin
    Muhammad Fahmi Zainuddin
    Dear All Currently I setup new Lab to test Web Server Protection to have better understanding regarding on how to it works. I trying to provide web server protection for public user to access my internal web server . Below is my network topology…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web Server HTTP Header Information Disclosure

    Alireza Bavi
    Alireza Bavi
    Hello everyone, I have a question regarding the usage of the command 'set http_proxy add_via_header off' in the CLI. We currently have a website and multiple host services, and we are considering disabling HTTP header information disclosure by request…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • URL redirection with Sophos XG

    rexer
    rexer
    Hi all Am I correct in assuming that URL redirection as it was possible in UTM can no longer be implemented with XG 19.x? We would like to forward Visitors of our Homepage (which is a webserver behind a webserver protection / WAF rule) from ourdomain…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Webserver Protection for Host behind IP tunnel

    Linus Haake
    Linus Haake
    Hello everybody, I'm currently trying to establish the WAF setup for the current confirguration: Two sites are connected via IP Tunnel and everything is properly working with the static routes set-up. Now we have the need to setup Webserver Protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall - Web Application Firewall (WAF)

    John_Kh
    John_Kh
    Hi, I configured the WAF on XGS87 (SFOS 19.5.2 MR-2-Build624), created the protection\authetication policies and applied them on the Firewall Rule. However, when I point the IP address of the published application, the login prompt to enter the username…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SFVH (SFOS 19.5.2 MR-2-Build624) New WAF bug throwing Error 404 on authentication

    Saarbruecken
    Saarbruecken
    When making any changes to a WAF rule, form based authentications will stop working and throw an error 404. When editing the affected authentication policy and saving the settings, which reloads WAF, the problem is gone. This can be reproduced on two…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Having issues with WAF rules with 2 web servers - XG v19.5.0

    Luke Bartley1
    Luke Bartley1
    Hi All, I am trying to have the following setup on my XG unit. sub1.mydomain.com -> internalwebserver1 sub2.mydomain.com -> internalwebserver2 I have created 2 WAF rules on my XG unit, both of them have the FQDN of the public website in the domains…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF error "ModSecurity: Request body no files data...."

    Regex
    Regex
    Hello, Im hosting for myself some things. One of it is PingVin-Share which is behind WAF on XG. I was trying to upload a file abut 10mb... But im getting an error. So i went to console -> advanced shell logs are below: [Sun May 14 20:00:11.856339…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF for Web-Server behind IPsec-Connection

    SM-ITM
    SM-ITM
    Hello, I have the problem with an XGS 107 (19.5.2-B624) that a web server (10.203.111.101), which is located behind an IPsec connection, is not reachable via the WAF. When accessing the web server via the Internet, I get the code 503. However, the problem…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web protection

    Stuart James
    Stuart James
    If I upload a new certificate because it's just been renewed, and then select that certificate in an existing firewall rule for web protection, it automatically deletes all the domains I've associated and puts in the ones it's found in the certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WEBSERVER AND WAF

    abdellah adil
    abdellah adil
    I have a local web server i would like to publish it so i can access it from outside via port 443 , i've already generated an ssl certificate and i would like to use it via Sophos FW . is it possible to do it via WAF and attach the new SSL certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • protect internal webserver

    chanklish
    chanklish
    hello i have 2 different webservers running in my internal network how should i protect them in my sophos from external attacks ? thank you
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos UTM: Create WAF to allow traffic through Exchange 2016

    Dennis Huagan
    Dennis Huagan
    Disclaimer: The content is published as-is, without any expectation of official support or guarantees. Please contact Sophos Professional Services if you require assistance with your specific environment. Overview This article contains steps to create…
    • over 1 year ago
    • UTM Firewall
    • Recommended Reads
  • Web Server Protection XGS

    Muhammad Fahmi Zainuddin
    Muhammad Fahmi Zainuddin
    Dear All I currently setup new lab to test Web Server Protection at XGS firewall. My setup: 1. Web Server using Xampp (LAN Zone) - IP: 192.168.100.2 2. Virtual Firewall XGS. (LAN Interface IP: 192.168.100.254) ( WAN Interface IP: 192.168.43…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
<>