• Sophos WAF

    Ilham Izzuddin Bin Sulaiman
    Ilham Izzuddin Bin Sulaiman
    Hello, I have a Peplink WAN gateway and a Sophos in the centre for routing from the core switch to the WAN.I have a problem: I cannot perform a waf for my webserver, which is hosted by peplink and the server are located at dmz, and my website is already…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Zweiten Webserver hinter Firewall

    ChrisV
    ChrisV
    Hallo zusammen, ich betreibe eine XGS 116W und würde gern einen zweiten Webserver hinter der Firewall erreichen können. Aktuell läuft schon einer tadellos. Aaaaaber ......... Sobald ich einen zweiten hinterlege (Richtlinie, Nat, Host usw…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • German Forum
  • Web server protection skip filter but no rule ID

    Carlo
    Carlo
    Hello, I have trouble configuring WAF rule for one specific web server/service When I try to access service from inside on my pc I get 403 [Sun Jan 07 19:40:08.983664 2024] [authz_core:error] [pid 22769:tid 140041007253248] [client 10.2.1.10:52039…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • SFOS 20, Exchange 2019, WAF Active Sync

    Marco Walbert
    Marco Walbert
    Hi, i read a lot of posts about this Problem, but cant get it running. Made the WAF settings strictly by Sophos KB article, owa, outlook anywhere etc are running properly, but active sync isnt working. Log saus WAF Anomaly Inbound…
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • Webserver hinter XGS erreichen

    DATA Admin
    DATA Admin
    Hallo zusammen, ich habe folgendes Problem. Ich habe eine UTM auf eine XGS umgezogen. Nun gehen folgende Verbindungen nicht mehr. Wir haben ein Firewall die hält das Server und das DMZ Netz zwischen dieser Firewall und der XGS besteht ein Transfernetz…
    • 11 months ago
    • Sophos Firewall
    • German Forum
  • Does Web server protection (WAF) support HTTP/2 in SFOS v20?

    IT Racom
    IT Racom
    I've been reading some discussions about WAF support for HTTP/2 before. Is it available in the new SFOS v20? Or is it planned for some next MR?
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • WAF - Static URL Hardening error

    FFin
    FFin
    SFOS 19.5MR3 I'm getting multiple WAF-Logentrys with exact same URL (upper-/lowercase) - one request passes correctly the other one fails due to "Static URL Hardening - No Signature found". As it's same exact same URL it's probably not a configuration…
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • WAF not working after Upgrade to SFOS 20.0

    EDV
    EDV
    We have updated our XGS3300 to SFOS 20.0 a few days ago. Since then our WAF ist not working. AH00526: Syntax error on line 106 of /cfs/waf/reverseproxy.conf: Invalid encrypted key AH00112: Warning: DocumentRoot [/sdisk/waffiles/1cf6480d9dcdd33a4319301e0d8ef22b…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos SFOS WAF Rules limit

    admin_idl
    admin_idl
    Hello, We use the Web Server Protection of Sophos XG Firewall and have now reached almost 60 WAF rules. This is also the maximum number of WAF rules. Is it possible to combine several URLs in one WAF rule and route them to different servers? WAF rule…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Is it possible to offload HTTPS on the Sophos fw and send plain HTTP to the real server ?

    Jochen Siers
    Jochen Siers
    Is it possible to decrypt HTTPs on the firewall and send plain HTTP to the webserver (without encrypting it again)? Thanks!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF & large files – how do you deal with it?

    dirkkotte
    dirkkotte
    Hi all, When AV or other protection features are enabled, we keep running into various problems while uploading large files. Sometimes the disk space (Temp=100%) seems to be the cause, sometimes other internal buffers. We have the requirement to allow…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SFOS 19.5.3 MR-3: Web Server Protected, Path-Specific routing - should this config work?

    gavo_nz
    gavo_nz
    Hi, I have a WAF rule configured for path-specific routing, however, the routes I am specifying are all to the same target web server, but with different restrictions. e.g. / - restricted to specific IP ranges, target sevrer1 /myapp/ - not restricted…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Order of domains in WAF rules

    Martijn Bouman
    Martijn Bouman
    XGS Firewall, WAF rules has 10 listed domains. What is the sort order based on for these domains? Whenever we delete one from say position 5, add a few new ones, then add the number 5 one again (we have saved and reopened the rule multiple times)…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • is it possible to combine SFOS WAF with the built in OTP / MFA function

    LHerzog
    LHerzog
    I found some old posts (>2y ago) about the XG WAF module not supporting MFA authentication for a webservice. Has this changed since? We want to use MFA before using on-prem Exchange OWA. Many internal users already have an Sophos MFA token and it…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF rules and IIS redirects with trailing slashes

    Martijn Bouman
    Martijn Bouman
    Situation. We have a WAF rule with several test sites in the domains list. Example below. test1.testurl.com test2.testurl.com test3.testurl.com test4.testurl.com These all point to one IIS. On the IIS these are all separate sites. When we…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS, WAF für Windows RDS Server 2022 mit Rollenaufteilung

    Loranus Pain
    Loranus Pain
    Hallo Community, Ich prüfe aktuelle das Setting mit einer XGS ( SFOS 19.5.3 MR-3-Build652) und dem Windows 2022 RDS. Die Rollen RDS Web und Gateway laufen auf einem dedizierten Server, der RDS Session Host und RDS Lizenz Server sind ebenfalls ein jeweils…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Incorrect WAF SSL Certificate Served To Client

    haydenspence
    haydenspence
    Hi. I am facing an issue with the Web Application Firewall. I have several WAF rules configured, some using SSL and other are not. They point to a central web server. The domain name is used to differentiate each web app and that is forwarded on to…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF and RDG 2019

    MarcKOUSSOU
    MarcKOUSSOU
    Hi all, SFOS 19.5 Just got a problem with WAF and RDG 2019, i can't log to my server and i have this error: /rpc/rpcproxy.dll WAF Anomaly Inbound Anomaly Score Exceeded (Total Score: 13) Hope i will find…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Webserver Protection - Zertifikat ist nicht auswählbar

    KarstenFL
    KarstenFL
    Moin, ich muss mich zum ersten Mal mit der Webserver Protection auseinandersetzen. Dabei habe ich das Problem, dass ich beim Anlegen einer neuer Firewall Regel, das Zertifikat nicht auswählen kann. Was habe ich bisher gemacht? 1. Das Zertifikat…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • WAF Authentication Forms shows 404 after upgrade to SFOS 19.5.3 MR-3-Build652

    Sergejs Guridi
    Sergejs Guridi
    After upgrade - all WAF with authentication form with template shows 404. Opening and saving Protection Policy - does not solve the issue. Recreation of Authentication Policy - does not solve the issue. Reimporting form template - does not solve…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web Server hinter Site2Site nicht erreichbar

    Jan Esders
    Jan Esders
    Hallo zusammen, leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter. Folgende Situatiion: Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • How to config waf without domain

    cy z
    cy z
    I want to set up a WAF on the firewall, but a domain needs to be set in the WAF rules. My server does not have a corresponding domain, how should I set it? I checked the official website manual, but I don't quite understand the statement in the manual…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS webserver protection on port 8080

    Joerg Seyfried
    Joerg Seyfried
    Hi y'all, I am struggling with the following scenario: Webserver protection works fine for several sites. Now I would like to protect an internal web service that should be available via https (yes, http S ) on port 8080 (I know...). Webserver Protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF - Rule greift nicht, Verständnissproblem?

    Matthias Rieche
    Matthias Rieche
    Hallo zusammen, ich wollte mich mal mit den WAF Möglichkeiten beschäftigen. Grad das Path-Specifig Routing ist für mich interessant. Ich habe jetzt 2 VM´s in der DMZ, jeweils mit Apache2 auf Port 80 (alles Testhalber). Ich habe jetzt wie im Screenshot…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Confused rule id and broken WAF rule.

    Michal Talman CZ
    Michal Talman CZ
    Hi, I'm having trouble with the WAF, XGS 2300 v19.5.1 I add the webserver web .xxx.xxx - it has policy ID 129 . But if I go to web .xxx.xxx in the log it shows that web.xxx.xxx has policy ID 43 . I get a 503 error But the policy ID 43 is spsluzba.xxx…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
<>