• Certificate renewal fail

    André Besteiro
    André Besteiro
    Hi, Our certificate for the site expires today and we've tried uploading a new one and it's imported but it's listed as untrusted. It's an Alpha SSL certificate and our service provider gave us the .csr and .key file. We copied the contents of the…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • on Sophos Firewall, if I update and regenerate the default CA, what are the implications?

    Callum Roseneder1
    Callum Roseneder1
    On Sophos Firewall, if I update and regenerate the default CA, what are the implications? I have a firewall that is setup, the default CA hasn't been customised so far. I need to setup a S2S IPsec VPN with certificates and wanted to customise this before…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Too much certificates in ovpn file

    Gerd
    Gerd
    While troubleshooting a SSL VPN connection I tried different certificates, which I successfully added as "trusted" in the Certifcates section of the WebUI. When I download the ovpn-config file from the VPN portal I found that every time I try a new…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • SSL VPN and certificates

    Andrej Pirman
    Andrej Pirman
    Hi, One thung bothers me regarding SSL certificates. I will have some 30 SSL VPN users on XGS , and I intend to install commercial SSL certificate. But it only has 1 year validity. Does it mean I will need to push .OVPN config to end users every year…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • WAF SSL Certificate Problem

    Nazir Ahmad Heravi
    Nazir Ahmad Heravi
    Dear All, I am facing with a Problem in sophos xg web server Protection, I have created all needed ruls and upload the ssl certificat to xg but in web application rule under the Host server when I select the HTTPS in the dropdaown menu I dont see me…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • How to allow guest user for accessing internet and connect to their office using Cisco AnyConnect VPN

    Robby Sirwaturai
    Robby Sirwaturai
    I have a dedicated VLAN in our network and a dedicated AD username for guest users. I am not using Sophos wireless network, I use another brand wireless network. I am using SFOS 19.5.3 Every time my guest users browse the internet after logging into…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS Lets Encrypt HTTP Challenge

    Fritz Otlinghaus
    Fritz Otlinghaus
    Hey everybody, as we could not find any working solution in the discussion forum that does the Lets encrypt Process on the Sophos itself, we setup a process to run the whole thing on the sophos firewall it self. Our blog post https://blog.helsinki…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • OpenVPN SSL Peer Certificate Verification Error

    JeffCooper
    JeffCooper
    Hi, We have a XGS2300 (SFOS 19.5.3 MR-3-Build652 with an SSL Remote Access VPN with OpenVPN clients. Not sure if this was a Sophos or OpenVPN issue but I had to start somewhere. I had a user call last last night with a Peer Certificate Verification…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • HTTPS decrypt and scan - not identifying embedded URLs

    rfcat_vk
    rfcat_vk
    Hi folks, a question about decrypt and scan that has me puzzled for sometime. The users have the XG certificate installed and functioning correctly except for Apple sites. I have web policies blocking advertisements and use the XG proxy, this functions…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS 2100: Certificate Authority: Invalid or Not Installed

    Graboid$
    Graboid$
    Hi Team, I uploaded a new PositiveSSL Cert (mail.company.com) for our Exchange On-premise email and I am getting an error "Certificate Authority: Invalid or Not Installed" We have a wildcard certificate (*.company.com) and it was recently renewed…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS136 admin console from LAN application certificate.

    DamienML
    DamienML
    Hi, What am I doing wrong? I have been administrating a new XGS 136 firewall and for some reason accessing the admin console on the LAN side has always reported the https certificate as not valid despite the fact the ApplianceCertificate is trusted…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Stop! This website is blocked

    Dragos Avram1
    Dragos Avram1
    Hello everyone, Recently i noticed a bunch of tickets regarding the following. i want to go on facebook, but facebook is blocked. instead of the blocked page i get Error code: SEC_ERROR_UNKNOWN_ISSUER(firefox) or NET::ERR_CERT_AUTHORITY_INVALID…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: How to use Microsoft Subordinate CA for SSL Inspection

    Jaydeep
    Jaydeep
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. ______________________________________________________________________________________________________________________________________…
    • over 4 years ago
    • Sophos Firewall
    • Recommended Reads
  • Frase de acceso o clave previamente compartida

    Salud Darien
    Salud Darien
    buenas tardes quiero subir mi certificado ssl generado por godaddy.com y me pide una frase compartida. la cual no tengo idea donde se pone. me podrían ayudar. gracias adjunto imagen
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: [LetsEncrypt] How To in Sophos Firewall

    LuCar Toni
    LuCar Toni
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview Update My Setup Certbot…
    • over 6 years ago
    • Sophos Firewall
    • Recommended Reads
  • Sophos Firewall: LetsEncrypt with Sophos Firewall and Sophos Factory

    LuCar Toni
    LuCar Toni
    Update: V21.0 supports Lets Encrypt onboard: Sophos Firewall v21 Early Access Announcement Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with…
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
  • Unable to Connect VPN due to SSL CA Certificate Expired

    Help Desk IT-ops
    Help Desk IT-ops
    Hello. We have a client using Sophos Firewall installed in a VM. ( Firmware 17.5.12) They are have expired SSL CA Certificate and when they applied new SSL CA Certificate, it shows error and VPN users unable to connect. So, now they are using expired…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • touch /var/certcache/.clear_all_certs_on_reload - touch not a valid command

    Gavin Rodgers
    Gavin Rodgers
    Having issue registering firewall, guides show to clear certs, but im getting a notice saying the touch is not a valid command. Clear certs post Sophos Firewall: Purging expired certs from Sophos Firewall Rest certs post Registration loop thanks…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Our WMS is sending notification emails but they are bouncing on the firewall but there no logs on the firewall

    mulah
    mulah
    Our WMS is sending notification emails but they are bouncing on the firewall but there no logs on the firewall The vendor for the WMS system sent us the logs from their side and the certificate being displayed is saying Cyberoam and we are using sophos…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Incorrect WAF SSL Certificate Served To Client

    haydenspence
    haydenspence
    Hi. I am facing an issue with the Web Application Firewall. I have several WAF rules configured, some using SSL and other are not. They point to a central web server. The domain name is used to differentiate each web app and that is forwarded on to…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG with POP3 Scan

    Gerald Werner
    Gerald Werner
    We use a Sophos XGS87 (SFOS 19.5.3 MR-3-Build652) and we want to use POP3 Scanning in legacy mode. In document ( https://doc.sophos.com/nsg/sophos-firewall/18.5/help/en-us/webhelp/onlinehelp/AdministratorHelp/Email/HowToArticles/EmailConfigurePOPIMAPScan…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos (XG) Client Authentifikation Agent

    Ben@Network
    Ben@Network
    Hallo all, I am currently looking for a lean solution to build a rule per firewall that only applies to authenticated users. I have connected the firewall to the AD and installed the "Client Authentification Agent" on the (Windows) client. The user…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Unable to download Self-Signed CA certificate for SSL VPN Sophos Connect

    Werner Smit
    Werner Smit
    Good Day, I am trying to download our Self-Signed Certificate from the Firewall to deploy to all users to prevent users from seeing a certificate error when signing on to the Sophos Connect SSL VPN. There is no download button on the firewall what…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sectigo Certificate Status Not Trusted

    Trio Fandi
    Trio Fandi
    I have import both Certificate and Root CA in Certificate Authorities Menu. But Certificate status Not Trusted persist. I saw a weird description in subject of certificate appears in Sophos. There is a different description between Certificate Menu…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos - Certificate authority: Invalid or not installed

    André Besteiro
    André Besteiro
    Good afternoon, When we accessed Sophos through the browser, we got an insecure certificate alert. We imported a new certificate into Sophos (the same used on our website), but the following message appears in the certificates menu: Certificate…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
<>