• 90% of Incoming DNS Requests Blocked, But Why?

    AlatarK
    AlatarK
    It's become apparent that about 90% of the incoming external DNS requests are being blocked at the firewall. Config: Our public NS1 is a Windows 2012R2 server, running in a DMZ. There is a simple DNAT rule (Any -> DNS -> External IP ==> Change dest…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • UTM Firewall - How to implement an allow list?

    Martin Rowe1
    Martin Rowe1
    Hello, I'm trying to create a simple allow list (whitelist) in in the SOPHOS UTM Firewall for a particular site, leaving all other sites unaffected. See the following configuration screen; Rules 9 and 10 are the ones of interest. Rule 9 is attempting…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Sophos UTM Client VPN Error (Authenticate/Decrypt packet error: packet HMAC authentication failed)

    mbrehm
    mbrehm
    Hi we got the problem that all oure VPN-Client users get 3-6 Times a Day the following error: Wed Mar 31 08:50:18 2021 Authenticate/Decrypt packet error: packet HMAC authentication failed Wed Mar 31 08:50:18 2021 Fatal decryption error (process_incoming_link…
    • over 3 years ago
    • UTM Firewall
    • General Discussion
  • DNAT and IP-Filter do not block traffic

    Chris69
    Chris69
    Hi there, today I really had to block traffic coming from a specific IP going to my UTM 9.705-3 trying massive IPSEC logins. Adding a firewall rule at #1 position did not work so I added a DNAT-rule to NAT all traffic coming from this IP going to…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • DNAT XG86w

    Andreas Schneider2
    Andreas Schneider2
    Hallo, möchte eine dnat regel anlegen um die Ports 49152-50175 zur telefonanlage zu öffnen. Bin wie folgt vorgegangen Host angelegt: IP Telefonanlage Dienst angelegt mit Quellport 49152:50175 Zielport 49152:50175 Über Serverzugriffsassistent…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • German Forum
  • Sophos XG 125w + Lancom R883+ als exposed Host und SIP Trunk (Telekom, DeutschlandLAN) mit Unity OpenScape

    Andr3as93
    Andr3as93
    Guten Morgen, ich verzweifle gerade ein wenig an unserer Telefonanlage. Folgende Thematik: Wir haben eine Sophos XG 125w (18er Version) Firewall hier hängen 3 Netze dran (1x Vodafone DSL, 1x Telekom DSL, 1x Telekom SIP Trunk). Ich habe probleme…
    • over 3 years ago
    • UTM Firewall
    • German Forum
  • UTM 9.7 SSL - SSL VPN allows Local Network Access when only Internet IPv4 is configured

    thehihatchi
    thehihatchi
    Hi Guys, I'm running the latest UTM 9 (version 9.705-3). I have the following configuration: LAN 1: 10.10.1.0/24 LAN 2: 10.10.2.0/24 SSL VPN Pool: 10.10.3.0/24 Everything works fine. I can log in with VPN users and they get allocated an IP address…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • General Discussion
  • Sophos UTM as Backend Firewall Design

    Sally
    Sally
    Hello, i use Sophos UTM Home since years now, and im really happy with it:) But as the Sophos UTM is still missing the Open VPN Client possibility, and DNSCrypt DOH is also not possible, i was thinking to add an other FW as Fronted Firewall to configure…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Sophos XG230 to Draytek 2960 IPSec VPN

    Alan Moon
    Alan Moon
    I have five Draytek 2960 running IPSec VPNs to a Sophos XG230. The Drayteks initiate the connection using IKE2. I get an email from the Drayteks every 53 minutes saying the link dropped. (It reconnects.) IKE Phase 1 timeout is 28800 seconds, Phase…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Creating rule to allow connection with various IP in subdomain

    mattin
    mattin
    Hi, mattin here. Im using SG Sophos and stuck just now. I want to add rule to allow connections via SG firewall to one service which is using some ports (which I know and can configure) and - as destination - is connecting to external servers which they…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Firewall-Regel richtig einstellen

    Fikret
    Fikret
    Hallo liebe Mitglieder, kurze Frage. Ich möchte von A > Any > B auch wieder zurück B > Any > A Erklärung: Ich möchte zB. Mit meinem Notebook A das Notebook B per Ping erreichen können und auch umgekehrt. Meine Frage: Richte ich das beidseitig…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • German Forum
  • Poor IPS perf - "Multithreaded" snort not working?

    Cooper Dickson
    Cooper Dickson
    Hi all. I have a custom built router using a Gigabyte J1900N-D3V board. To cut it short, inter-VLAN traffic is limited to about 200mbit, but the CPU utilization only ever hits ~30%. Of course standard snort does not take advantage of the multiple cores…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Feature request: Adobe is now blocking Flash content, why can't we?

    SalishSwede
    SalishSwede
    Currently, the UI in the UTM allows blocking active content which includes ActiveX, Java, and Flash. Flash is now obsolete and considered risky to use at all. The manufacturer is now blocking it. I propose the UI be chanced to allow for the blocking…
    • over 3 years ago
    • UTM Firewall
    • General Discussion
  • load balancing

    guet saleh
    guet saleh
    We are adding 2 WAN connections next week I have reviewed as much documentation as I can but I cannot determine the best and correct configuration to achieve this. both new WAN lines are working 1st mainline microwave and the 2nd fiber we want to creat…
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • load balancing

    guet saleh
    guet saleh
    We are adding 2 WAN connections next week I have reviewed as much documentation as I can but I cannot determine the best and correct configuration to achieve this. both new WAN lines are working 1st mainline microwave and the 2nd fiber we want to creat…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • TCPdump download from webadmin is encrypted?

    Michael Romagnoli
    Michael Romagnoli
    So I am attempting to download a pcap file from x.x.x.x.com/tcpdump.pcap similar to what is outlined in https://support.sophos.com/support/s/article/KB-000038909?language=en_US . I am writing the file to /var/sec/chroot-httpd/var/webadmin/tcpdump…
    • Answered
    • over 3 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Bridged Mode: Cant ping wan

    Teererai Marange
    Teererai Marange
    Complete Noob here trying to get started. To this point I've done the following: My goal setup is as follows: WAN->router->utm->internal network. utm is running in microsoft hyper-v . Configured a bridged interface as follows: 2. Added the following…
    • Answered
    • over 4 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • SophosUTM (Alixboard) ist eine Performancebremse

    tomily
    tomily
    Guten Morgen Sophos Kollegen, habe zwar ähnliche Posts gelesen, aber keinen in meiner Konstellation. Deshalb wage ich es mich mit einem separaten Eintrag an euch zu wenden: Ich habe eine SophosUTM9 (aktueller Patchlevel) auf einem Alixboard laufen…
    • over 4 years ago
    • UTM Firewall
    • German Forum
  • Remote Access - Dyndns

    feroz syed
    feroz syed
    Hello, is there anyway to setup SSL VPN without static ip, there is no option on ssl vpn configure to define the public domain name. This option available on XG and it working fine, but UTM i don't see way to setup remote access without static ip.
    • over 4 years ago
    • UTM Firewall
    • General Discussion
  • GOOGLE MEET VIDEO CALL

    echebureche
    echebureche
    Hi Everyone, I would like to ask for your help regarding google meet. When we are inside our private network we can call someone outside our private network using google meet, audio is fine and we are able to see the video of the person on the other side…
    • Answered
    • over 4 years ago
    • UTM Firewall
    • General Discussion
  • Portweiterleitung > Firewall/NAT

    Indimundur
    Indimundur
    Moin! Augenscheinlich bin ich für das einfachste Vorhaben zu doof, denn ich will eine stumpfe Portweiterleitung konfigurieren. Umgebung: Homeedition, Version SFVH (SFOS 18.0.3 MR-3) WAN: Hängt im Fritzbox-Netzwerk TESTCASE: Daran ist eine VM angeschlossen…
    • over 4 years ago
    • UTM Firewall
    • German Forum
  • Can't get VoIP traffic out on UTM 9. Firewall rules in place, packets still getting dropped.

    Davroc Ltd
    Davroc Ltd
    Hey guys, having an issue with our UTM here. So we're trying to go hosted VoIP, but having issues getting traffic out of our UTM to hit the host servers. Strange thing is that the mobile app for our provider works fine, on the network, but the desktop…
    • Answered
    • over 4 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Question about XG and SG firewalls and appliances

    DeltaSM
    DeltaSM
    Hello, We currently have a Sophos UTM SG 210 (REV 1.0). We also have a Fullguard license with Premium Support which expires in January 2021. I'm looking to replace for SG 210 unit and renew the license. We are glad of this solution. However, before…
    • Answered
    • over 4 years ago
    • UTM Firewall
    • Hardware, Installation, Up2Date, Licensing
  • Vacuum Robot Firewall Rule App Management

    Sally
    Sally
    Hello, i have my vacuum bot installed and connected to my home wifi. I can manage the bot via the app on my smartphone, working fine. But i saw, when im out of the house, not connected to Wifi, and connected to GSM Connection and start the Robot Management…
    • over 4 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • Firewall Rule bound to specific interface

    rbremer
    rbremer
    Dear Community I am faced with a specific issue regarding firewall rules. By default, you can only filter IP networks/ranges, which is fairly sufficient in most cases. However, we need to filter out certain IP ranges coming from in on two interfaces…
    • over 4 years ago
    • UTM Firewall
    • Network Protection: Firewall, NAT, QoS, & IPS
  • View related content from anywhere
  • More
  • Cancel
<>