• Attempt to communicate with a botnet is detected - My threat hunting thus far

    Hey Help Desk Guy
    Hey Help Desk Guy
    Hi everyone, So like a lot of others here I've experienced where we get the notification that an attempt to communicate with a botnet or command and control server has been detected. And its always these same three sites: As you can see…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Application Control change request via support case

    LHerzog
    LHerzog
    Hi, some users of us are using a business website that has an Application (not Web) categorization as Vulnerabilities (besides others) for some years now. It's just when you even call the start page, that the firewall blocks request. That causes me…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Apllication Filter stuck on loading Sophos xg 19

    Magy
    Magy
    whenever i open a rule the application filter stuck on loading i restarted it but se ems weired to me.. any fix?\
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block POrt Scanning and Public IP

    Don Osi
    Don Osi
    Hello, I have a sophos xg can you share a way to block publicip from scanning for open ports and also how can you blacklist an IP address.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Rules to allow access remotely with ANYDESK (lan to wan)

    Fotit
    Fotit
    Hi all , i need to allow anydesk for some administrators (lan to wan) i make this config below but it doesn't work ! Where's the problem? Source zones=LAN Source networks and devices=any During scheduled time=all the time Destination zones…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall App control without Endpoint Agent?

    Wolfgang Jacques
    Wolfgang Jacques
    We have a customer who uses Sophos Firewall (SFOS 19.5) but has a third party antivirus tool. So no Endpoint Agent and no Intercept X is installed on the client PCs. Does it make sense at all to use App control in the Firewall Rules in this scenario…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Blocking Tiktok

    UJay
    UJay
    Hi I am using XG-115 FW. What is the easiest way to block TikTok? Read number of articles published in the community and noticed that different people are talking different methods. I am confused. Hence looking for a simple answer with simple instructions…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Veeam B&R 12 issue

    twister5800
    twister5800
    Hi all, Upgraded customers to Veeam Backup and Replication to version 12, an started seeing theese on the backup copy jobs, for the remote repositories: 03-04-2023 14:29:31 :: Processing Error: An unknown error occurred while processing the certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Application filter keeps getting overwritten

    FAAC Inc
    FAAC Inc
    Hello. After importing some firewall rules from another XGS3300 running 19.5.0 over the weekend, each morning I'm coming in to find that we can't access the internet. When I check the application filter for "Block high risk (Risk Level 4 and 5) apps"…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ATP alert

    Don Osi
    Don Osi
    Hello am getting this alert sara-tabuk.no-ip.biz as an ATP threat can you assist?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Signature Sinkhole

    Jirayu Siangsai
    Jirayu Siangsai
    Firmware version 17.0 have this signature but firmware version 18.5, 19.0, and 19.5 do not have this signature. Can anyone have firewall firmware version 19.5.1 and search in IPS policies have this signature and capture image reply me pls.. Thanks in…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • How to block ChatGPT website and app

    David Laude
    David Laude
    I'm having a hard time blocking ChatGPT and can't even find it in application control. Please help, thank you!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block XVPN servers

    Hugo José Gongora Lozano
    Hugo José Gongora Lozano
    Good morning We have an end customer (a school) where students use iPads. It turns out that there are several students who have caught the bad habit of getting IPs from proxy servers thanks to the XVPN application. They do not use it on the iPads, but…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Can I disable a single Signature ID within IPS?

    AllanD
    AllanD
    We have software that goes out to a distributors website and downloads updates. Part of these updates is a batch of Word documents in .docx format that have some ActiveX controls in them that are used for automation. They cannot be removed and are a normal…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Why is DNS over HTTPS classified as High Risk?

    tscott_16
    tscott_16
    In Application usage report, DNS over HTTPS is classified as High Risk. Why? I would think HTTPS is always preferable. Is it because it imposes limitations on what the firewall can see and control?
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • False Positives

    FAAC Inc
    FAAC Inc
    Hello, we are having some trouble with Zoom meetings where the sound is briefly dropping at times. Sometimes we get the network quality message. I may have traced the problem to some of the meeting traffic getting flagged as Proxy and Tunnel (x-vpn…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPS and SSL Inspection best practice

    Krystian Kamiński
    Krystian Kamiński
    Hello I wondering how effective can be IPS in XGS series without decrypting SSL traffic. It is worth to configure without ssl inspection when i want to protect web servers (IIS, nginx, apache)?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block all IPs on known Abuse list

    April Beachy
    April Beachy
    I would think this feature should be readily available, but I am unable to find a way to do this. I want to block all IPs that appear on known abuse lists from our network. We are running an XG firewall. So far the rule blocking IPs by country has…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 19.5 IPS Email Alert Flood - SMTP DoS?

    Corey Carpenter
    Corey Carpenter
    My org had an event last week where a false positive IPS alert was being thrown. This caused over 1400 email alerts within 20 minutes before anyone could get to it and shut it down. When I looked at the email logs it looks like it was sending 3-4 emails…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Are there plans to include an "anti-portscan" feature in sophos XG?

    alan weir
    alan weir
    The UTM has an essential feature called "anti-portscan" that is seperate from DoS protection.Anti-portscan, if you are not aware, will detect when a source IP address is scanning the external WAN interface for open ports, and block, drop, or log the source…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS116 appears to be blocking FortiClient SSLVPN

    Daniel Bingham
    Daniel Bingham
    Hi, I run an XGS116 and have a requirement to connect to a company who uses FortiGate 100's. They have supplied me with the FortiClient SSLVPN client. If I connect to the VPN, I can not ping external addresses such as 8.8.8.8. I had their MSP…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Is the XStream / Zero-Day feature worth it in your personal opinion?

    JohnnyInc
    JohnnyInc
    Hi everyone, I am administrating about 15 Sophos UTMs still managed through SUM and we are thinking about to use the XGS for future renewals at our customers. That said, do you think the XStream option is needed / a must have or it the standard protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Facebook videos

    Ahmed Said Abdulhai
    Ahmed Said Abdulhai
    it blocked videos on sites like YouTube and facebok from applications, I think it will block all videos on other sites, I am not sure if that is the best practice but anyway its working with me. there is One thing remaining I can't figure it, the Facebook…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block Anydesk general

    Francis Picoli
    Francis Picoli
    good afternoon everyone, I need help. I need to block anydesk on all company computers. how could i do this lock? blocking the application or creating some specific rule? I look forward to returning, thank you.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt. It started this morning.

    Francois Taljaard
    Francois Taljaard
    Keep on getting this notification email every 5 minutes from XGS2100 firewall. Affects only one user's computer. FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt. It started this morning. Please assist. These four IP's external are listed so…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>