Hallo zusammen,
seit Donnerstag bekomme ich ständig die Warnung mit folgender Nachricht:
Message: Access from IP address '92.53.65.166' is blocked for '5' minutes after '5' unsuccessful login attempt.
Unsere Firewall ist
Alert for XGS2100…
On September 4, our Firewall VPN Portal was attacked from IP 92.53.65.166 (Russia) with hundreds of login attempts for different usernames. After bloicking this, today (September 8) we have been hammered by another attack, this time from hundreds of different…
Since today we have been experiencing massive password spraying attacks on many Sophos firewalls, especially on the VPN portal, which listens to port 443. Apparently these are attacks from Russia with the IP 92.53.65.166. How can I create a rule to prevent…
hi,
if I scan the WAN IP from my Sophos Firewall, i can see open Ports, like:
PORT STATE SERVICE 21/tcp open ftp 22/tcp filtered ssh 23/tcp filtered telnet 25/tcp filtered smtp 53/tcp filtered domain 80/tcp open http 110/tcp filtered pop3 111/tcp…
So i'm a bit confused and could use some help. After running NMAP on my public IP for a sanity check i was greeted with ports showing open that shouldn't be available to the WAN port. I don't have any services checked on my local service ACL for WAN Starting…
Hi, i'm working on getting the correct ICMP firewall rules on my Sophos Firewall.
For doing this i've created a Local Service ACL Execption rule using the service "Ping/Ping6" for my WAN zone and allowing only some common route we use, excluding the…
Hello,
I'm running web server on port 443 in DMZ zone with another service running on port 7xxx.
I can browse web page because of waf rule, but I can not connect to service on port 7xxx from WAN, Packet capture show ACL Violation
Show…