• IPS problem "OS-LINUX Linux Kernel Netfilter iptables-restore Stack-based Buffer Overflow"

    Charlie Dodd
    Charlie Dodd
    Hi All, hope you can help. Ive recently been getting a lot of alerts with this as can be seen in the image below. searching with some of the IP addresses on greynoise it shows it as commonly seen and it is nothing to worry about. i have seen that…
    • 3 days ago
    • Sophos Firewall
    • Discussions
  • Veeam Guest Interaction Proxy creates false IPS Alerts

    Peter Riederer
    Peter Riederer
    Hey, after deploying our new XGS3300 with SFOS v21 we noticed several IPS Alerts which are created from a Veeam Guest Interaction Proxy to the Veeam Backup Server: Attack : FILE-OTHER Adobe Premier Pro ibfs32.dll dll-load exploit attempt Attacker: Guest…
    • Answered
    • 15 days ago
    • Sophos Firewall
    • Discussions
  • ips.log filling at high rate - normal and good for the SSD lifetime?

    LHerzog
    LHerzog
    Today we've had a partial outage due to high /var partition usage. It was flapping between 70% and over 90% in a short time. /dev/var 179.3G 138.6G 40.7G 77% /var /dev/var 179.3G 138.8G 40.5G 77% /var /dev/var 179.3G 138.9G 40.4G 77% /var /dev/var…
    • Answered
    • 17 days ago
    • Sophos Firewall
    • Discussions
  • Malware 'Unscannable' was detected and blocked in a download from acroipm2.adobe.com

    Maroun Moussallem
    Maroun Moussallem
    hello, The last two days, we've been receiving an http virus mail from sophos firewall with the following message, (Malware 'Unscannable' was detected and blocked in a download from acroipm2.adobe.com). what we had done so far, full scan launched…
    • Answered
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • FreePBX triggers Network attacks - protocol-voip

    148Points
    148Points
    Hi, all of a sudden we see that our FreePBX installations triggers Network-attacks in our XGS. "Attacker" is our FreePBX, 192.168.1.22 - "Victim" is the IP of our SIP-Trunk Provider. Attack : PROTOCOL-VOIP Contact header format string attempt. This…
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • intrusion attack

    Charlie Dodd
    Charlie Dodd
    Hi all, im pretty new to the sophos firewall i noted that on the dashboard it showed an attack and also checked the logs whcih are both shown below. From this i can see that it was detected rather than blocked. Is there a way to set the IPS to block by…
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • IPS alerts every 30 mintues (signature ID 2310195)

    support_einsal
    support_einsal
    Hello everyone, Since yesterday, we have been experiencing a consistent IPS alert from our firewall (XGS Vers. SFOS 20.0.2 MR-2-Build378 ). The affected connection is between our email gateway/proxy in the DMZ and our mail server. Every 30 minutes…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Microsoft Internet Explorer PNG tRNS chuck size 1 information disclosure attempt

    Maroun Moussallem
    Maroun Moussallem
    hello, I got this intrusion attempt for the first time. just don't know what to do. I looked for any recent downloads and browsing history, and asked the user if he plugged any device to the computer but nothing suspicious found. this is a screenshot…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • CVE 2021-20090

    Maroun Moussallem
    Maroun Moussallem
    hello, Alert Message: Message: SERVER-WEBAPP Arcadyan Routers CVE-2021-20090 Path Traversal Attempt I got this Alert today, and the attacker is one of the company's computer, I read an article about this vulnerability…
    • Answered
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Request for Advice on Attack-FILE-IMAGE ImageMagick SyncExifProfile Out Of Bounds Array Indexing

    Michael9609
    Michael9609
    Dear Member I hope this message finds you well. I am currently encountering a significant amount of network traffic related to the Attack-FILE-IMAGE ImageMagick SyncExifProfile Out Of Bounds Array Indexing alert. the firewall ais detecting and dropping…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Firewall default IPS policies

    DavidSain
    DavidSain
    I found https://community.sophos.com/sophos-xg-firewall/f/discussions/110856/default-ips-policies/397166?focus=true, didn't help. Sophos pre-packages some IPS policies by default. Without having to go through each of them with a fine toothed comb, is…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Cannot send Viber attachment on desktop version but successful on mobile version

    ArnelC
    ArnelC
    Cannot send Viber attachment on desktop version but successful on mobile version. Just migrated from XG210 to XGS2100 with latest firmware SFOS 20.0.1 MR-1 Build 342. No problem in fresh setup on XGS2100 both desktop and mobile version on Viber. Thank…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPS not applying to policies

    Elmo Heyns
    Elmo Heyns
    Hi All Ive spent some time on the Sophos documentation but I'm unable to get to an answer via the available online resources. I have a firewall with a few basic rules. Unrestricted internet policy - less web and app filter restrictions based on…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Block Impacket, psexec, Windows RCE

    MMASLOUH7
    MMASLOUH7
    Hello, Im doing some POC to chose the best firewall that have a good NGIPS. The default IPS profile was not able to block Impacket, psexec or any other Windows RCE. How can i made the IPS policy more strict for a LAN to LAN policy.
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • TCP Disconnect with IPS-Pattern updates ??

    dirkkotte
    dirkkotte
    We have some customers who use quite sensitive software. We have had repeated session drops with one customer (always at noon on Tuesdays -GMT-) The IPS patterns are said to have been updated at this time today. IPS is only active for some external connections…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to setup Network attack protection

    Søren Jensen
    Søren Jensen
    Hello All, I am a newbee to XG, but have been using UTM9 for some years. In UTM9, I could see a number of attacks being dropped every day. After I changed to XG (version SFVH [SFOS 20.0.0 GA-Build222]) I do no longer see any attacks. I have activated…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Block internet access for PowerShell

    Luis Prunn
    Luis Prunn
    Hello Community, one of our customers requested whether we could block internet access for powershell in order to prevent sideloading of any malicious modules or scripts. On the SG firewall, I already tried adding an application block rule for…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • DDos sophos XG

    mohammed kassouat
    mohammed kassouat
    hi, can you please show me a template for DOS best practices and proof protection
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • How to block advanced ip scanner

    William Nascimento - SGI
    William Nascimento - SGI
    How to block applications such as advanced ip scanner from scanning the network? my product is sophos xgs 2300
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Trusted MAC address CSV

    abish
    abish
    Hello Community Members, I want to enable DoS & spoof protection in my Sophos XGS2100. But, To enable it for all the hosts there will be a lot of trusted MAC addresses so adding them manually is a time-consuming process. So I came across this article…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Help with this.

    Edgar Leon
    Edgar Leon
    Hi Sophos community any solution for this issue. Message: SERVER-OTHER multiple products blacknurse ICMP denial of service attempt
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • SERVER-WEBAPP SNIProxy new_address Stack Buffer Overflow

    Edgar Leon
    Edgar Leon
    Need help with this issue in sophos Message: SERVER-WEBAPP SNIProxy new_address Stack Buffer Overflow
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • IPS Log Messages: Anomaly - Removed the urgent flag and pointer in TCP header / Enforces IPS protection

    philbert
    philbert
    For some time, we get the following IPS Log Messages: Example 1 2024-01-16 12:12:20 IPS messageid="06001" log_type="IDP" log_component="Anomaly" log_subtype="Detect" ips_policy="" ips_policy_id="0" fw_rule_id="140" fw_rule_name="x1" fw_rule_section…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Alert ID 7002

    Pradeep
    Pradeep
    Hi team I am getting this alert frequently from the firewall. please help me to resolve this
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • Intrusion prevention alert (Critical)

    Sofos network
    Sofos network
    Hello, I have this alert today: intrusion prevention alert, but i don't know how to check or to diagnose this
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
>