• ATP alert

    Don Osi
    Don Osi
    Hello am getting this alert sara-tabuk.no-ip.biz as an ATP threat can you assist?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Signature Sinkhole

    Jirayu Siangsai
    Jirayu Siangsai
    Firmware version 17.0 have this signature but firmware version 18.5, 19.0, and 19.5 do not have this signature. Can anyone have firewall firmware version 19.5.1 and search in IPS policies have this signature and capture image reply me pls.. Thanks in…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • How to block ChatGPT website and app

    David Laude
    David Laude
    I'm having a hard time blocking ChatGPT and can't even find it in application control. Please help, thank you!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block XVPN servers

    Hugo José Gongora Lozano
    Hugo José Gongora Lozano
    Good morning We have an end customer (a school) where students use iPads. It turns out that there are several students who have caught the bad habit of getting IPs from proxy servers thanks to the XVPN application. They do not use it on the iPads, but…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Can I disable a single Signature ID within IPS?

    AllanD
    AllanD
    We have software that goes out to a distributors website and downloads updates. Part of these updates is a batch of Word documents in .docx format that have some ActiveX controls in them that are used for automation. They cannot be removed and are a normal…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Why is DNS over HTTPS classified as High Risk?

    tscott_16
    tscott_16
    In Application usage report, DNS over HTTPS is classified as High Risk. Why? I would think HTTPS is always preferable. Is it because it imposes limitations on what the firewall can see and control?
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • False Positives

    FAAC Inc
    FAAC Inc
    Hello, we are having some trouble with Zoom meetings where the sound is briefly dropping at times. Sometimes we get the network quality message. I may have traced the problem to some of the meeting traffic getting flagged as Proxy and Tunnel (x-vpn…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPS and SSL Inspection best practice

    Krystian Kamiński
    Krystian Kamiński
    Hello I wondering how effective can be IPS in XGS series without decrypting SSL traffic. It is worth to configure without ssl inspection when i want to protect web servers (IIS, nginx, apache)?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block all IPs on known Abuse list

    April Beachy
    April Beachy
    I would think this feature should be readily available, but I am unable to find a way to do this. I want to block all IPs that appear on known abuse lists from our network. We are running an XG firewall. So far the rule blocking IPs by country has…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 19.5 IPS Email Alert Flood - SMTP DoS?

    Corey Carpenter
    Corey Carpenter
    My org had an event last week where a false positive IPS alert was being thrown. This caused over 1400 email alerts within 20 minutes before anyone could get to it and shut it down. When I looked at the email logs it looks like it was sending 3-4 emails…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Are there plans to include an "anti-portscan" feature in sophos XG?

    alan weir
    alan weir
    The UTM has an essential feature called "anti-portscan" that is seperate from DoS protection.Anti-portscan, if you are not aware, will detect when a source IP address is scanning the external WAN interface for open ports, and block, drop, or log the source…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS116 appears to be blocking FortiClient SSLVPN

    Daniel Bingham
    Daniel Bingham
    Hi, I run an XGS116 and have a requirement to connect to a company who uses FortiGate 100's. They have supplied me with the FortiClient SSLVPN client. If I connect to the VPN, I can not ping external addresses such as 8.8.8.8. I had their MSP…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Is the XStream / Zero-Day feature worth it in your personal opinion?

    JohnnyInc
    JohnnyInc
    Hi everyone, I am administrating about 15 Sophos UTMs still managed through SUM and we are thinking about to use the XGS for future renewals at our customers. That said, do you think the XStream option is needed / a must have or it the standard protection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Facebook videos

    Ahmed Said Abdulhai
    Ahmed Said Abdulhai
    it blocked videos on sites like YouTube and facebok from applications, I think it will block all videos on other sites, I am not sure if that is the best practice but anyway its working with me. there is One thing remaining I can't figure it, the Facebook…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block Anydesk general

    Francis Picoli
    Francis Picoli
    good afternoon everyone, I need help. I need to block anydesk on all company computers. how could i do this lock? blocking the application or creating some specific rule? I look forward to returning, thank you.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt. It started this morning.

    Francois Taljaard
    Francois Taljaard
    Keep on getting this notification email every 5 minutes from XGS2100 firewall. Affects only one user's computer. FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt. It started this morning. Please assist. These four IP's external are listed so…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • During upgrade to XGS 19.5 firmware, got more than 70 email alerts for HTTP virus detected

    DG1
    DG1
    While upgrading the firmware on my HA stack of sophos XGS 3100, I got more than 70 email alerts for the HTTP virus detected Alert ID: 8001 with the messages below repeatedly: Malware 'Unscannable' was detected and blocked in a download from crl4.digicert…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ATP Exceptions is not working

    Alexandre LANTOINE
    Alexandre LANTOINE
    Hello everyone, I have a problem with two FW (one on Azure, one XG) We have a lot of detections like this (ATP) We saw that this URL centos.brontocdn.com is legit and it's an official Centos Repo. I allowed it here : But both FW are still…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Denied OpenVPN connection still transferring data

    Wilbur Chung
    Wilbur Chung
    I have a strange issue today. I have a firewall rule to block OpenVPN connections in place and it seems to work. However, today I discovered data is still being transferred even the connection is denied. I can see from the firewall log the connection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block TikTok on Sophos Firewall

    libru keney
    libru keney
    Hi I find odd that none of the major firewalls on the marketing have an built-in option to block or control major social networks like TikTok. TikTok and Instagram are by far one of the worst things for the bandwidth and productivity. Rants asside…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPS Time of signature update issue.

    Ashfaq Shah
    Ashfaq Shah
    Dear Friends, We have recently upgrade our Firewall XG310 to latest Firmware ( SFOS 19.0.1 MR-1-Build365) , now we are facing issue in IPS Time of signature update which shows 23:08:29, Nov 11 2022 and the Pattern Updates for IPS and Application signatures…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN issue

    muhamad sherzad
    muhamad sherzad
    dear guys we have sophos XG firewall device , now when we block the VPN is working fine on iphone but in android system VPN not blocked so i mean VPN applications will block on iphone but in android still working and the applications on android and…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Block VPN Exntesion/Add-on On Chrome, Opera browser

    Nazir Heravi
    Nazir Heravi
    dear all, I asked this question 9 months ago but unfortunately, still I have no solution for it although I have installed the Security Appliance SSL CA on the end user's machineI've Sophos XG Home that block all Entertainment Web Browser. Problem is…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Lastpass blocked by application filtering (Block high risk (Risk Level 4 and 5) apps)

    Jurre Mijs
    Jurre Mijs
    Hi Sophos Community, I was wondering for a while why some of our customers couldn't reach the Lastpass website. Now I have discovered that its being blocked by application filtering with filter "Block high risk (Risk Level 4 and 5) apps". I am aware…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Behaviour of Application Control

    Manuel Karl
    Manuel Karl
    Good Monring, I've an XGS v19.0.1 and want to set an Application Filter (AC) on top of existing Firewall rules. But i'm not sure if i'm understanding how this mechanism is working. My fw-rule is from "serveral internal zones" with "several defined…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>