• Packet Capture filtering

    DavidSain
    DavidSain
    We manage 241 firewalls via Central for our customers. We have management from the internet locked down. When performing a packet capture in the WebUI, there is a "Display Filter" button. If I want to filter on a specific rule, I have entered the Rule…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • How to find out IP-Adresses of incoming ipsec vpns at sophos xgs firewall

    msw_fisit
    msw_fisit
    We have a sophos xgs with several ipsecn vpns site to site running. the Sophos XGS is responding to some VPNs that are without fixed public ipv4 adresses. One VPN incoming has no fixed static ip adress, but i need to enter that ip-adress at xgs to…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • When MAC Filtering is enabled, clients with correct password but not on the Whitelist are not appearing in system logs when attempting to connect to the wireless network

    alan weir
    alan weir
    SFOS 19.5.1 I have wireless protection enabled in SFOS using a Sophos AP. I recently created an MAC host group with a whitelist of MAC addresses of devices that can connect to the wireless network. Recently an Android device that was previously authenticated…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • networkd.log file questions

    MarkThornton
    MarkThornton
    Where can I find a description of the messages I find in the networkd.log? I'm looking for how to tell what might be going wrong with the wan dhcp request on my port2 on one of my XGS107's that is unable to renew an ip address. Can I disable the GuestAP…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS logfiles unavailable with WinSCP?

    MarkThornton
    MarkThornton
    I have used WinSCP with my XG firewall to read the logfiles because I'm not a linux propeller-head guru. Now I'm having an odd WAN dhcp problem on my new XGS firewall, when I go to the logs up pops a dialog box saying /logs/tslog is empty. What's up with…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Reports disk Usage reached 90% exceeding the higher watermark of 90%

    Nehal Modekar
    Nehal Modekar
    Hello, We have received the alert notification "Reports disk Usage reached 90% exceeding the higher watermark of 90%". Kindly guide me before doing purge how I can download that data and then purge.
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • IPS Logging

    Paul McGinnie
    Paul McGinnie
    How does one enable logging (so one can see it in the Log Viewer in the management web interface) of IPS events. Every time I have a IPS problem, I get email notifications but the IPS Log Viewer tab is empty - how can i get it to populate? Regards…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Log and Drop (IPv6) firewall rule "Allowing" and "Denying"... huh?

    Wayne Folta
    Wayne Folta
    I have a firewall rule (rule 20) which is a "log and drop" rule at the bottom of the IPv6 rules. But I'm seeing something very weird: some of the time it says "Denied" and some of the time it says "Allowed". There are no exceptions in the rule. Not only…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Looking at awarrenhttp_access.log for FQDNs

    Brian1941
    Brian1941
    I have an XG125w (SFOS 18.5.2 MR-2-Build380). A while back, I had a website that needed a web exception for SSL/TLS decryption and scan. The domain needed did not appear in the SSL/TLS log viewer. I opened a ticket with support and they gave me some…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Bounced message errors, where are they, why are they unavailable

    MarkThornton
    MarkThornton
    I am very disappointed in the error reporting functionality of the XG v18 firewall. Actually, the error reporting just isn't useful at all. Today I have a bounced message due to certificate issue on the recipient end. But the only way I know that is a…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Home XG 18 MR4 - Incorrect usage reported for sessions over 4GB

    Alan Panec
    Alan Panec
    Hi I have noticed weird logging and reporting behavior on the XG when transfering more than 4GB during one connection session. I tried to reboot the firewall, but no difference. You can see results of some of my tests below. Reports and policy counters…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • Is it possible to see the DURATION of an SSL VPN connection? The logs show almost nothing

    Sidney Frey
    Sidney Frey
    Hi, I have tried opening a support ticket as well as searching on these forums but I cannot seem to get a straight answer. I'm using an XG450. With Covid making work from home mandatory for a lot of employees, management is now asking me to produce…
    • Answered
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • Missing Button to show where an object is used and its last change

    Bernd Siempelkamp
    Bernd Siempelkamp
    How can i see if and where a Host- or Group-Definition ist used in XG Konfiguration? With UTM every Entry had a Button for this. why is it not realized in actual Software Release
    • over 4 years ago
    • Sophos Firewall
    • Discussions
  • Reports for Clientless Access

    John Henry Vindas Carballo
    John Henry Vindas Carballo
    Hello, I have been testing the use of clietless access VPN with a customer and we found that there's not info on the reports for this VPN. We are using those bookmarks to give access through RDP to some servers. Alls the bookmarks works and the users…
    • Answered
    • over 4 years ago
    • Sophos Firewall
    • Discussions
  • Delete Users Logging on XG v18

    LHerzog
    LHerzog
    I created and deleted some local users on XG. Logging for creation is OK - I can see who created a user and see the username of the new user. When deleting, the user name field is empty and the usernames that had been deleted are not logged. It just…
    • over 4 years ago
    • Sophos Firewall
    • Discussions
  • Log Comp is Exporting DHCP Server Logs

    mehmet sinansahin
    mehmet sinansahin
    Hi; Is it possible to export the log viewer to the dhcp logs that appear in the Log Viewer. date - based. 2018-10-16 23: 08: 27SYSTEMmessageid = "60020" log_type = "Event" log_component = "DHCP Server" log_subtype = "System" status = "Renew" leased_ip…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Where can i find SSL vpn connection logs

    itguy318
    itguy318
    I am unable to find the logs for the remote SSL vpn users on the reports dashboard. I am able to find only the username and internal ip the sophos xg has issued to the user. I cant see time, date of connection including what public ip address from where…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • script to to retrieve the sslvpn log

    Ajmal Younas
    Ajmal Younas
    Hello, Does anyone know a a scriptable way to retrieve the system/event logs of the firewall? please let me know some automated method. thanks
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Integrated iView with sophos XG

    Huy Vu
    Huy Vu
    Hi all, I trying integrate sophos XG with iView (SIVOS 03.01.2) , but nothing is sent to iView by XG ( SFOS 17.1.0 GA) . My configuation: iView: XG: what happened?
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Graph shows high usage

    BLS
    BLS
    Wow....I have a much faster internet connection that I could possible imagine...and one that would have 99.9% of the worlds population in envy! Never even knew I had a connection that was 214TB :) Joking aside - is there anyway to be able to fix the…
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Possible to log all detected applications without blocking them?

    tscott_16
    tscott_16
    I'd like to get a feel for what applications are being used on the network but it seems the Application log only shows what is blocked. Is there any way to monitor application usage without actually blocking them?
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Access Historical Admin/user Logs

    Joe Plunkett
    Joe Plunkett
    Hello, I am looking for a way to dump all of the admin logs. If I am in the GUI log viewer, the section titled 'Admin' is what I am looking for, but I want those logs going back further than the GUI provides. I have looked in the /log directory from…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Forward ModSecurity Logs

    Wahyu Nuryanto
    Wahyu Nuryanto
    Hi Guys, I am new to Sophos XG Firewall and currently i am working to integrate Sophos XG with OSSIM for security event monitoring (SIEM). I am able to forward all logs to the OSSIM but there is one more logs that i can not send to the SIEM, yes it…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Seeing outbound email detected as spam - but coming from external ip - how to track via logs

    Aaron Berger
    Aaron Berger
    Hey Guys I've enabled outbound spam filtering on my XG 115W firewall as I was ending up on email blacklists. I've also got an Exchange 2010 server running behind the firewall. I'm getting some weird outgoing email traffic in my XG firewall. In the…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Can't remove the logs even after flush/purge the reports

    l0rdraiden
    l0rdraiden
    I can't remove the logs even after flush/purge the reports. Why? it's possible to do it? By the way ATP logs are enable in the settings but don't appear in the logs even with I filter, do I have to enable the log in the LAN->WAN firewall rule? or…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
>