• Advanced Threat Protection C2/Generic-A

    Edward Raja
    Edward Raja
    Hi , We are facing this issue. Any solution for this?
    • 5 days ago
    • Sophos Firewall
    • Discussions
  • Issue with Third-Party Threat Feed Not Blocking WAN to LAN Traffic

    Jurgens Steyn
    Jurgens Steyn
    Hi, I’m using a third-party threat feed with Sophos and under the impression that it should provide WAN to LAN protection. However, I’ve conducted a test and observed unexpected behavior. Here’s what I did: Created a custom text file list containing…
    • 18 days ago
    • Sophos Firewall
    • Discussions
  • X-Ops seems not to be working on V21 GA?

    EdmundSackbauer
    EdmundSackbauer
    Hi, I moved to Version 21.0 GA (Home Edition) recently. I noticed that in control panel, no events in the log or counters are logged that X-Ops is doing anything: A configured third party threat list (abuseipdb.com) is working properly and blocks…
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • botnet prevention

    Kiran Jedhe
    Kiran Jedhe
    Hi, Can we enable botnet prevention on the SFOS firewall. Please provide any kind info related to this.
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Problems with Veeam B+R 12.1 and SFOS 20.0.2 MR-2-Build378 - failed to create NFC download stream

    Peter Riederer
    Peter Riederer
    Hey Folks, we rolled out a XGS126 in our Branch yesterday (before SG125) and we cannot get Veeam to work backing up our Branch VMs. The Branch is connected via IPSEC VPN Tunnel to our Datacenter (Sophos SG310). I already found the older thread Veeam…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Is there a way we can see the detailed reports for alerts in Advance Threat? Such as IP and etc? We only see the device number

    Gideon Orozco
    Gideon Orozco
    Currently we are using Sophos XGS 4500 and we are receiving alerts in Advance Threat however it only shows the device (see image below). Is there a way where we can see a detailed reports such sa IP and etc? Also, what is the "X45007...." device indicated…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • advanced protections

    Apai Debnath
    Apai Debnath
    How to configure Advanced Protection on Sophos Firewall ? Suggest me why we use this option.
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • What ist the benefit of IPS, Zero-Day Protection, ATP and web filtering without deep packet inspection on TLS sessions

    Dr No
    Dr No
    stupid question, I know, but honestly: what is the benefit of the Xstream protection when you decide not to break TLS sessions at all (besides mail filtering)? Will someone earn any higher protection level with all these features activated without breaking…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS ATP Alert (No Host Name or Threat)

    Peter Mastrangelo
    Peter Mastrangelo
    Today our XGS started reporting ATP sources blocked without a Host Name, IP, or Threat. There is also no information under Monitor & Analyze > Reports > Network & Threats: Advanced Threat Protection How do I go about tracing down the issue? …
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Changing ATP Settings: "The operation will take time to complete. The status can be viewed from the "Log viewer" page"

    LHerzog
    LHerzog
    Whenever I click Apply in ATP, I can see the spinning circle and after some time the message " The operation will take time to complete. The status can be viewed from the "Log viewer" page ". It does not matter if I change somethin, add hosts or whatever…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ATP Event XGS

    admin_idl
    admin_idl
    Hello, we have the message "an attempt to communicate with a botnet or command and control server has been detected sophos xgs". This message occurred simultaneously on 2 firewalls at 2 different locations. What further measures are recommended here…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Clearing Zero-Day Protection log

    BruceGiles
    BruceGiles
    Running SFOS 19.5.2 MR-2 on an XG310. In the Zero-day protection section of the Control Center, it shows 0 Recent, 274 Incidents, 330 Scanned. When I click on that, it goes to the Zero-day protection logs, and I get two pages containing a total of 38…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ZERO DAY ALERT

    Anonymous123
    Anonymous123
    There are a number of zero day security alerts on my Sophos firewall tab coming from Chrome Installer. Any help would be appreciated! - The machine learning analysis and sandbox analysis shows no signs of bad intension and the overall file hash shows…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Attempt to communicate with a botnet is detected - My threat hunting thus far

    Hey Help Desk Guy
    Hey Help Desk Guy
    Hi everyone, So like a lot of others here I've experienced where we get the notification that an attempt to communicate with a botnet or command and control server has been detected. And its always these same three sites: As you can see…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Veeam B&R 12 issue

    twister5800
    twister5800
    Hi all, Upgraded customers to Veeam Backup and Replication to version 12, an started seeing theese on the backup copy jobs, for the remote repositories: 03-04-2023 14:29:31 :: Processing Error: An unknown error occurred while processing the certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ATP alert

    Don Osi
    Don Osi
    Hello am getting this alert sara-tabuk.no-ip.biz as an ATP threat can you assist?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Why is DNS over HTTPS classified as High Risk?

    tscott_16
    tscott_16
    In Application usage report, DNS over HTTPS is classified as High Risk. Why? I would think HTTPS is always preferable. Is it because it imposes limitations on what the firewall can see and control?
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ATP Exceptions is not working

    Alexandre LANTOINE
    Alexandre LANTOINE
    Hello everyone, I have a problem with two FW (one on Azure, one XG) We have a lot of detections like this (ATP) We saw that this URL centos.brontocdn.com is legit and it's an official Centos Repo. I allowed it here : But both FW are still…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • connection with bad ip address

    Ahmad
    Ahmad
    hi, if i have sophos XGS or XG and from lan my users start making connection with bad reputed ip address. then can firewall block it??? ATP is same or it is different? can SOPHOS XG/ XGS also consult some IOC Feed ???
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • XG450 Advanced Threat Protection -> C2/Generic-A -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe - False Postive Alarm?

    EDV-Support
    EDV-Support
    Hello, we are using : Sophos XG450 (SFOS 18.5.1) During the last 2 weeks we recceived the following Security Warnings on 2 different Computers: Was ist passiert: Ein Computer hat schädliche Daten versandt. Das lässt darauf schließen, dass er mit…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos suddenly detecting Trusteer Rapport?

    zeban sho
    zeban sho
    Noticed ransomware alert from a PC with C:\Windows\System32\msiexec.exe but drilling down I can see it's Trusteer Rapport. I have about a dozen machines with this software though and none of the others are alerting. I'm 99% sure it's a false positive…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Alerts C2/Generic-A

    Guilherme Silva1
    Guilherme Silva1
    Dear, We are facing a very strange situation regarding the very frequent alerts we are getting for C2/Generic-A. Most of these alerts have origin addresses, from DNS servers, such as 8.8.8.8 for example, but what is intriguing is what in the details…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • An attempt to communicate with a botnet or command and control server has been detected.

    Chris Anthony1
    Chris Anthony1
    Hi Everyone! Can anyone help me? I received several reports from XG Firewall that a n attempt to communicate with a botnet or command and control server has been detected. The source IP is Google's DNS (8.8.8.8 and 8.8.4.4) and my DNS (203.167.97…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • An attempt to communicate with a botnet or command and control server has been detected.

    MJ_P1
    MJ_P1
    I found some malware on a client PC not long ago, which we discussed at length in this thread: https://community.sophos.com/intercept-x-endpoint/f/discussions/132693/mal-polazert-a-removal/491955#491955 . Intercept X is deployed throughout the network…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Advanced Threat Protection research

    William Capeless
    William Capeless
    I am having trouble determining what is happening here. I see the source is google dns, the destination is my internal dns server. the threat is clickmatters.biz. How do I track this down to find out what is going on. I checked web logs to see if anyone…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
>