• Is Sophos IPS able to detect CVE-2020-1472 based attacks?

    LHerzog
    LHerzog
    CVE-2020-1472 Zerologon is about to go into the wild. Is XG able to detect those logon attacks with IPS?
    • Answered
    • over 4 years ago
    • Sophos Firewall
    • Discussions
  • Best Practice for RED Tunnel firewall rules and routes?

    john_kenny
    john_kenny
    Ive been using XG and UTM for a while now and have used RED a few times, but ive got a dedicated server now in the cloud and i installed XG on it for my edge firewall. I setup a red tunnel from my xg to that xg but i had a windows 2019 vm running on the…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • IPS problem with youtube site

    Ramy Sayed1
    Ramy Sayed1
    I am facing a problem with IPS service when stopping it every thing is going well,when starting it youtube.com can't resolve and not opening even I can't ping it ,in the same time I can open any other site,the only change I did with IPs that I changed…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • utf8 filename transfer attempt - what does it mean ?

    Ladislav Benes
    Ladislav Benes
    Firewall blocked an email. I do not understand why . Log: 2018-10-20 14:30:19IPSmessageid="07002" log_type="IDP" log_component="Signatures" log_subtype="Drop" ips_policy="" ips_policy_id="7" fw_rule_id="71" user="" sig_id="12597" message="SERVER-OTHER…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Logs for DDOS blocked attack

    Deepak Verma
    Deepak Verma
    Dear All, I have configured DOS policy and I can see the packet dropped by the DDOS but where I can see the logs? I tried to find out in IPS, System, Firewall logs but no luck. Please help
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • SOPHOS XG or SG have IDS (Intrusion Detection System) or IPS only?

    Kidian Chavarria1
    Kidian Chavarria1
    I need to see if sophos (XG or SG) gather some requirements but I can't find information about IDS, can someone tell me if sophos (XG or SG) have IDS
    • Answered
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Security Configuration for Chrome OS

    Deepak Verma
    Deepak Verma
    Hi, We are planning for a big network (2500 Chrome OS Users) and I am asking a simple question about IPS configuration for the Chrome OS policies. There is no specific IPS signature for the Chrome OS in the XG firewall IPS (I didn't find on another…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • IPS action "Bypass Session" making confusion

    Deepak Verma
    Deepak Verma
    Dear All, There is an action in the IPS policy " Bypass Session" and as per documents " Bypass Session - Allows the entire session if detects any traffic that matches the signature." and recommendation for the same is: "To save resources and avoid…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • Tivo flagged with - Apache HTTP Server mod_rpaf x-forwarded-for Denial of Service

    Gary21
    Gary21
    I have noticed that my Tivo is being flagged by the IPS with "Apache HTTP Server mod_rpaf x-forwarded-for Denial of Service." There were 27 instances yesterday, with 3 noted IP address targets. Is this a false positive or something that I should be concerned…
    • over 6 years ago
    • Sophos Firewall
    • Discussions
  • #7672711 - Low bandwidth on Sophos XG 330 - Version SFOS 16.05.5 MR-5

    Desmond Besa
    Desmond Besa
    Hi Guys, I am experiencing really low bandwidth with the Sophos XG. I have tried turning of IPS, Web Filter, and Application control just to tshoot. Is there something with the OS version (SFOS 16.05.5 MR-5) that is causing this? Thanks. …
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • IPS alerts - Have I to be concerned?

    FormerMember
    FormerMember
    Hi, since I am using XG, I'am getting always IPS alerts, and I am concerned about, because I don't know the reason of these alerts. Are IPS alerts a alert about accessing websites with vulnerabilities or outdated software, or means an IPS alert…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • XG310 IPS Flagging Some Adobe Files but XG125 Is Not - Same firmware / pattern updates / settings

    AllanD
    AllanD
    We are having trouble downloading some Adobe Acrobat files from one of our vendors. The files are being flagged by the IPS system under the signature "Adobe Reader PDF Engine CVE-2017-3025 Memory Corruption Vulnerability". It only is affecting about 10…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Many IPS alerts

    FormerMember
    FormerMember
    Good morning everybody! I have many IPS alerts, is that normal? And not all of the victims IP's are in my network! I use LAN_TO_WAN standart IPS policy!
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • IPS not blocking EICAR signature

    Dean Jones
    Dean Jones
    I have a basic firewall policy set up with the default LAN_TO_WAN IPS policy enabled. I have downloaded a few different versions of the the standard EICAR test string and these appear in the firewall log under malware but they appear to make it through…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • Google Play Store blocked by IPS

    Gaustino
    Gaustino
    Hello, I am running XG Firewall for a few months now. However, I still have a problem which I could not solve yet. When trying to update my apps on my Android phone, Google Play Store keeps trying to download the updates. After several minutes I receive…
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • XG Best Practice, Firewall, IPS, VPN ect.

    AnthonyChallis
    AnthonyChallis
    Hi All, We have a new XG + Sophos central/interceptX. I have the firewall setup with a copy of LAN-WAN IPS with all but windows clients/servers removed, SSL decrypt+scan and yellow or above heartbeat policy setup. Is this how we should go or does…
    • Answered
    • over 7 years ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<