• Sophos XGS v20.0.2 - Heartbeat service dead - Decryption of passphrase is failed

    Jens Frankiewicz
    Jens Frankiewicz
    Hello, we performed a firewall migration from an XG450 model to the XGS4500 model last weekend. The firewalls are in a HA configuration. The migration process worked seamlessly. The primary firewall is working with no issue, all services started. To…
    • Answered
    • 22 days ago
    • Sophos Firewall
    • Discussions
  • Howto combine 'Match known users' and 'Block clients with no heartbeat'

    FFin
    FFin
    I could not figure out the details about traffic matching critera and further filtering within firewall rules. Can someone clarify what will happen if you select "Match known users" and "Block clients with no heartbeat"? Will the rule block no heartbeat…
    • Answered
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • firewall blocks client due to heartbeat - while the HB status is green <1> - why?

    LHerzog
    LHerzog
    Our firewall rules with block clients with no HB and green HB only enabled, blocked this client today during the HB status on the firewall was reported as green. I cannot see a reason - any idea? I don't like to create special rules for this client. The…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • how to diagnose Heartbeat SSL errors in heartbeatd.log - or why do they occur all the time?

    LHerzog
    LHerzog
    Heartbeat is always a bit tricky here. As we have several rules with block clients with no HB, the impact off technical heartbeat issues is always high. Endpoints have the latest official Client versions from Central. Currently 2024.2.3.4.0 For…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Firewall Synchronized Security information missing in Sophos Central.

    Randy Cleveland
    Randy Cleveland
    We have several Sophos Firewalls, and most of them are showing correct Synchronized Security information in Sophos Central. For Example: Two of these firewalls above aren't showing any data about Applications or endpoints. I've checked the firewalls…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Hearbeat (?) message customisation

    Gabriel Doring
    Gabriel Doring
    Hello, I've recieved a request from a client asking to change the message from this notification whenever a user that is connected to the cabled network and changes to the Wi-Fi network. I'm not sure if the message is being sent by the Firewall…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Packets dropped due to no heartbeat

    Stuart James
    Stuart James
    We have remote users to connect to a Sophos SSLVPN. We then create the following filewall rule between them and the servers to ensure that they have Sophos AV installed and that there are no issues on either side. Unfortunately, when we do this, no-one…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Central Heartbeat - behind 3rd party firewall?

    bmu
    bmu
    Hi, i'm actually setting up Sophos Heartbeat on a Sophos XG135 (Cluster). We're using Sophos Intercept X and Sophos Connect (SSL-VPN) on our clients. My setup with heartbeat used in firewall rules at our HQ seems to work without any issues; but i…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Security Heartbeat - LAN User blocken wenn nicht grün

    Admin TSK
    Admin TSK
    Hallo in die Runde, entschuldigt die evtl. etwas einfache Frage. Ich möchte gern der den LAN-Netzwerkverkehr eines Nutzers blocken, wenn sein Heartbeat nicht "grün" ist. Ich habe bereits Regeln angelegt, für den Verkehr zwischen LAN und VPN / RED…
    • 10 months ago
    • Sophos Firewall
    • German Forum
  • Security policy for hosts

    Gustavo Moreira
    Gustavo Moreira
    Is there any way to create a policy so hosts that are not in compliance cannot access the internal network? Example: If the host does not have AV and CrowdStrike installed and active, access to the internal network or VPN is not allowed, therefore,…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • When are Clients with no heartbeat allowed to rules with Heartbeat requirement?

    LHerzog
    LHerzog
    We have a rule that is configured with heartbeat like this: A device had heartbeat days ago but currently has no heartbeat. XG430_WP02_SFOS 19.5.3 MR-3-Build652 HA-Primary# ipset -L hb_green |grep 172.16.xxx.xxx XG430_WP02_SFOS 19.5.3 MR-3-Build652…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Security Heartbeat - Sophos Central

    Malte Söhner
    Malte Söhner
    Hello, I regitered my Sophos in Sophos Central and tried to activate Security Hearbeat. But I get following message: (sorry thats in german) Security Heartbeat ist aufgrund der Lizenzen nicht verfügbar. Überprüfen Sie Ihre Lizenzen. Wenden Sie sich…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • German Forum
  • Red Heartbeat when users share docking station

    LHerzog
    LHerzog
    We notice strange Heartbeat issues this week when users of one department started desk sharing. Users have indiividual notebooks with Intercept-X. The Network is connected to XG firewall SFOS 19.0.1. DHCP Server on the Network. XG gets the Heartbeat…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to debug Endpoint heartbeat "The network status has changed, the Firewall may disconnect."

    LHerzog
    LHerzog
    We have a client currently that is only connected with LAN. The client is reporting network changes the the firewall every few minutes and generates a new HB session. Causing many interruptins for the user. The client computer remains connected to the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Remove non-existing Clients from missing heartbeat list

    Hugo Moerenhout
    Hugo Moerenhout
    How to remove a non-existing endpoint from Sophos Firewall Control Center which shows the endpoint with "missing hearbeat" state 175 days ago. The endpoint was decomissioned and Sophos endpoint uninstalled and removed from Sophos Central about 6 months…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • heartbeat log: Cannot create ID for application, because appId range is exhausted. Application will be ignored.

    LHerzog
    LHerzog
    is that something to worry about in the heartbeatd.log? This is logged quite frequently on our SFOS 19.0.1 box [2023-03-16 14:18:04.039Z] INFO EndpointStorage.cpp[32722]:110 endpoint_connectivity_cb - Connectivity changed for <xxxxxxxxxxxxxxxxxxx…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • GUI -- Synchronized Application Control warning screen is causing graphics to not display properly in popup

    alan weir
    alan weir
    Sophos XG 19.5.0 GA When choosing Applications->Synchronized Application Control on the side menu, a warning pops up about enabling Synchronized application control. There is a bug that caused the window to not be sized properly.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Heartbeat service is not started after a fail over

    Keyur
    Keyur
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Hi Community, After restoring the backup on the HA enabled appliance…
    • over 4 years ago
    • Sophos Firewall
    • Recommended Reads
  • Cannot register with Sophos Central

    Carlo
    Carlo
    Hi, after I changed port type from dhcp (using firewall behind ips router) to pppoe (using fw to establish connection). I cannot register with Sophos Central using email and OTP or enable Red service. Internet works but quite slow (will open another…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos Intercept X with XG Home

    MikeyS
    MikeyS
    Is it possible to use Sophos Intercept X with XG Home?
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Security Heartbeat missing; but with SSL VPN its connected

    Dr Brezner
    Dr Brezner
    Hi Community, we have problems with missing heartbeats. following scenario: Branch office connected via IPsec to main branch, both XG. In the main branch there are resources that can only be reached with a heartbeat. Since a few weeks the clients…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Heartbeat stops showing any endpoint clients on GUI

    Arkita Thakkar
    Arkita Thakkar
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. ______________________________________________________________________________________________________________________________________…
    • over 2 years ago
    • Sophos Firewall
    • Recommended Reads
  • Heartbeat using wrong username

    Jakub Kavka
    Jakub Kavka
    Hello, is there any way how to tell Heartbeat function to use AD username format? By default its using "local" username format and every Heartbeat try ends up as failed. Strange is that some common users like "lunches (obedy)", "office dept" etc.…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Heartbeat Rules - can someone sneak in with foreign device with Sophos Endpoint?

    LHerzog
    LHerzog
    Hi, I have a quick question about Security Heartbeat. Imagine, you have a FW rule on your XG with Security Heartbeat enabled: green source, green destination No user authentication required on that rule. Now, someone not belonging to your company…
    • Answered
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • No live user displayed for Intercept X Advanced for Server

    JasP
    JasP
    I have recently noticed that all our servers with Intercept X Advanced for Server do not show the 'user' details in the logs and any user based firewall rules fail (obviously). This is with a user logged in via Remote Desktop. These are domain joined…
    • Answered
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
>