• Request for Advice on Attack-FILE-IMAGE ImageMagick SyncExifProfile Out Of Bounds Array Indexing

    Michael9609
    Michael9609
    Dear Member I hope this message finds you well. I am currently encountering a significant amount of network traffic related to the Attack-FILE-IMAGE ImageMagick SyncExifProfile Out Of Bounds Array Indexing alert. the firewall ais detecting and dropping…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Suddenly receiving IP_SPOOF Violations in XG 210 from allowed source

    Clay Tsuhako
    Clay Tsuhako
    Hello: Yesterday I started seeing these IP_SPOOF violations from our remote site that is on the allowed list in the DNAT firewall rule. They are unable to connect or ping our DNAT devices setup behind the firewall. We can connect to them with out…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Firewall default IPS policies

    DavidSain
    DavidSain
    I found https://community.sophos.com/sophos-xg-firewall/f/discussions/110856/default-ips-policies/397166?focus=true, didn't help. Sophos pre-packages some IPS policies by default. Without having to go through each of them with a fine toothed comb, is…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Problems with Veeam B+R 12.1 and SFOS 20.0.2 MR-2-Build378 - failed to create NFC download stream

    Peter Riederer
    Peter Riederer
    Hey Folks, we rolled out a XGS126 in our Branch yesterday (before SG125) and we cannot get Veeam to work backing up our Branch VMs. The Branch is connected via IPSEC VPN Tunnel to our Datacenter (Sophos SG310). I already found the older thread Veeam…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Cannot send Viber attachment on desktop version but successful on mobile version

    ArnelC
    ArnelC
    Cannot send Viber attachment on desktop version but successful on mobile version. Just migrated from XG210 to XGS2100 with latest firmware SFOS 20.0.1 MR-1 Build 342. No problem in fresh setup on XGS2100 both desktop and mobile version on Viber. Thank…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Block WPS office

    Raffa76
    Raffa76
    Hello, there's a way to block "WPS Office" from download? many thanks best regards
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPS not applying to policies

    Elmo Heyns
    Elmo Heyns
    Hi All Ive spent some time on the Sophos documentation but I'm unable to get to an answer via the available online resources. I have a firewall with a few basic rules. Unrestricted internet policy - less web and app filter restrictions based on…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • How to exclude tightvnc from Risk or High Risk application list

    Søren Jensen
    Søren Jensen
    Hello All, I have added the "Block high risk (Risk level 4 and 5) apps" to the " Identify and control applications (App control)" part of Lan-To-Wan Firewall rule. With this in the La-To-Wan firewall rule, I can not connect to a remote computer, using…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Block Impacket, psexec, Windows RCE

    MMASLOUH7
    MMASLOUH7
    Hello, Im doing some POC to chose the best firewall that have a good NGIPS. The default IPS profile was not able to block Impacket, psexec or any other Windows RCE. How can i made the IPS policy more strict for a LAN to LAN policy.
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Configuring IP Spoof and DoS Protection without Blocking Outbound Internet Traffic

    Yuvraj Singh
    Yuvraj Singh
    Hello Team, I hope this message finds you well. I am writing to seek your assistance regarding a configuration issue I am facing with our sophos xgs firewall setup. We have recently configured traffic flow and firewall rules for inbound and outbound…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Preventing Users from using any desk or Team viewer

    Reem Jalal Eddine
    Reem Jalal Eddine
    What is the best way to block users from using any version of Team viewer and Any desk and what ports have you used if we need to block ports? How to do that on Sophos?
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • TCP Disconnect with IPS-Pattern updates ??

    dirkkotte
    dirkkotte
    We have some customers who use quite sensitive software. We have had repeated session drops with one customer (always at noon on Tuesdays -GMT-) The IPS patterns are said to have been updated at this time today. IPS is only active for some external connections…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to setup Network attack protection

    Søren Jensen
    Søren Jensen
    Hello All, I am a newbee to XG, but have been using UTM9 for some years. In UTM9, I could see a number of attacks being dropped every day. After I changed to XG (version SFVH [SFOS 20.0.0 GA-Build222]) I do no longer see any attacks. I have activated…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • classify banking/financial services in the Application Object

    Guilherme Silva1
    Guilherme Silva1
    Hello, Do you have any recommendations for classifying financial services/banks and bank websites in the Application object? I need to use SDWAN for this type of service, but generally access to these sites are classified as "Secure Socket Layer…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Block internet access for PowerShell

    Luis Prunn
    Luis Prunn
    Hello Community, one of our customers requested whether we could block internet access for powershell in order to prevent sideloading of any malicious modules or scripts. On the SG firewall, I already tried adding an application block rule for…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Allow Firewall for Copilot

    LSG Admin-Venket
    LSG Admin-Venket
    Hello team, We would like to know which Category unblocks the Buil-in copilot that is coming with Microsoft Edge. Is there an exception be made specific to co-pilot alone?
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • STUN question about

    JohnMMM
    JohnMMM
    I noticed in The Logs from our Router that there is 1.25GB Upload on STUN and about 850MB Download STUN. Could someone please tell me what that could, I say could be ? Could it be video chatting over WhatsAPP OR FACETIME ?.
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • DDos sophos XG

    mohammed kassouat
    mohammed kassouat
    hi, can you please show me a template for DOS best practices and proof protection
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Bypass Application Control for client IP

    R Beatrix
    R Beatrix
    Hello Community, Is there a way to create a "bypass" for Application Control in Sophos Firewall that is applied to a client IP address? In the old UTM 9 interface, I used to be able to assign hosts to bypass lists, which would bypass all Application…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • I see a new entry in DoS protection called "IP Flood"

    alan weir
    alan weir
    Sophos v20 GA I have never noticed this IP Flood protection before. It is not applied, but I cannot see it's activation anywhere in the GUI. All I see activatable is SYN, UDP, TCP and ICMP, Dropped source routed packets, Disable ICMP/ICMPv6 redirect…
    • Answered
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Application Filter Categorisation Challenge

    ptho
    ptho
    Hi Sophos, A user at our org was sent a link to access a document online. This document was hosted by autoexel[.]info which doesn't flag up as malicious using any of the tools available to us, but the Sophos Firewall determines is a TOR Proxy, and…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • How to block advanced ip scanner

    William Nascimento - SGI
    William Nascimento - SGI
    How to block applications such as advanced ip scanner from scanning the network? my product is sophos xgs 2300
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Application Filter - blocking policy questions

    jspanitz
    jspanitz
    Ok unless I am missing something, you: Create an Application Filter, set it to Block. But in the GUI overview it shows default action is Allow. You have to edit the policy to see it's set to block. Poor design and visually confusing. Create a Firewall…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Blocking apps allows to block one of FQDN Host Group but not other

    New Temp
    New Temp
    I have two FQDN hosts : Instagram (*.instagram.com) and Facebook (*.facebook.com). These two FQDN hosts are added in an FQDN host group named Social Media. A rule in "Traffic to WAN" is configured for LAN to WAN that rejects this specific FQDN Host…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Trusted MAC address CSV

    abish
    abish
    Hello Community Members, I want to enable DoS & spoof protection in my Sophos XGS2100. But, To enable it for all the hosts there will be a lot of trusted MAC addresses so adding them manually is a time-consuming process. So I came across this article…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>