I have the below deployment on my environment
Devices/Servers
- Sophos XG 210 FW (Assigned it's own Public IP [i.e. x.x.x.67])
- Switch (Cisco ) - Connects all the APs and Servers
- 3 Server (1 Web server with it's own Public IP [i.e. x.x.x.68…
Good day, I am facing a strange issue with domain name resolution. Some domains are not resolved by XGS internal DNS. Below are nslookups from XGS Advanced shell. It used to work but suddenly stoped few days ago. Thank you for advice.
DNS Configuration…
Hi,
XGS2300 is our DHCP Server. Currently, DNS settings under Network > DHCP > Default_DHCP_Server are the gateway itself for the Primary, and our ISP for the secondary DNS Servers. Works fine.
Our external DNS servers (Network > DNS) are our ISP…
We have multiple ISP gateways per XG.
Is there a way to set DNS server preferences for each particular gateway?
WHY?
I've added NextDNS as an additional layer of security and for analytics to function properly for each profile I need DNS servers…
Hi all!
We manage DHCP and DNS for the end devices via the XG310. Since last week, the Internet connection of the clients is sporadically interrupted.
The end devices are correctly assigned IP addresses and DNS by the XG.
Neither nslookup or ping…
I am currently migrating the SG firewall configuration to XGS. After completing the configuration migration, it appears that the XGS firewall cannot query FQDNs properly. The same FQDN can be queried for two IPs in the SG firewall, but only one can be…
Hello everyone,
today the first occurences of DNS over TLS showed up in one of our customers logs. We have TLS Inspection rolled out at the company and are asking ourselves if the TLS Inspection also inspects DNS over TLS traffic and DNS over HTTPS…
Hi,
this issue is listed as resolved for 19.0.2
NC-111476 FQDN Subdomain learning isn't working in case of non-SFOS DNS server set for client.
We're on 19.5.2
We have a server that downloads files once per day from a FQDN like files.downloadserver…
Hi,
Encountering a weird error when trying to attempt using a server for DNS forwarding.
We have a few branch offices - each connecting to DC via IPSEC (Connection Type: Site-to-Site / IKEv2) - with the DNS Forwadering Host in the DC.
Now here's…
Curious if anyone's done this or sees value in it.
Our current scenario is we have our AD and integrated DNS hosted in an IaaS provider where no "end users" live. We have migrated all of the remaining Windows servers we have to this location. As part…
Hi;
I have 3 DCs for domain in my network.
111.local 192.168.1.11 PDC 192.168.1.12 ADC 192.168.1.13 ADC
192.168.1.1 is a SOPHOS LAN interface ip address
Under the DNS host entry, I entered these fields with the DC server ip addresses. (Network…
i have dns domain server 10.0.0.1 mask 255.0.0.0 gateway 10.0.0.2 & and ip range is 10.0.0.1 to 10.0.0.254 but now i want to give different ip range to different department like 10.0.1.1 to 10.0.1.254 to support department and 10.0.2.1 to 10.0.2.254 for…
Hello All,
We have a setup in which Sophos Firewall acts a hosted filter (VMware). Sophos Firewall acts as a central filter for 10 + sites - i.e internet traffic from 10 sites has to pass through central filter.
We have a plan to move sites to serverless…
Hello,
I am using Sophos XGS 3100 UTM device. For about 5-6 months, a DNS query has been made to lookingprovide.com every day and every hour of the day. Sophos ATP blocks this query (C2/Generic-A). When I examine the log records, I see that the source…
Environment:
Windows server only Central office with remote offices Each Remote office has DC with DHCP and DNS with it's own Sophos firewall. Each Firewall has connection back to central office firewall We recently had to change IP Schema.
The issue…
Hi folks,
this morning while testing some DNS issues, I changed the WAN interface DNS setting from manual to use DHCP, I refreshed the interface which was reported by the XG as the IP4 component down then up. I tested the settings by using the diagnostic…
Hi All,
I'm getting hostname resolution failures from docker containers for local DNS records; they seem unable to handle a rather strange response from the Sophos Firewall DNS service.
As far as I can tell, the problem is that the DNS server returns…
Hi all,
here is my environment:
HQ--------
FW XG
AD | DNS SERVER
Wbeserver: app.domain.corp
BO: (Workgroup)---------
FW XGS: DNS|DHCP|GW
There's Site To site IPSec config between HQ and BO .
I need to configure "conditionnal forwarder…
Hi
I have a clients XGS87, and the users cannot connect to office 365 for email. When I use policy tester with the url, I get error device could not resolve the url, please update url and try again.
When I go to DNS and test the name lookup, it is…
I've successfully configured our XG Firewalls to push logs to our SIEM solution which works well, though when trying to trace source of DNS requests I can't find anything logged either locally on the XG, or anything on the SIEM other than a UDP port 53…
I'm trying to setup DNS Request Route to a DNS server on AWS. Situation is similar to the below but I'm using Sophos Firewall instead of UTM. For SNAT on the Sophos Firewall, I can't seem to use a subnet so can't test the resolution that is mentioned…
We have two VLANs which are isolated from the rest of our network. They use external DNS for lookups. When the user hits a content issue, they are redirected to the firewall captive portal. However, because they use the external DNS they are pointed to…