• Assign a second public subnet to DMZ

    pgross
    pgross
    Hi, I'm using a XGS116 with SFOS 20.0.1 MR-1-Build342. I've got a public subnet 1 (2.1.1.0/30) assigned by the ISP. 2.1.1.1 is their gateway. 2.1.1.2 is used as static IP of PortF1 (ISP1). I've got a backup connection on Port3 (ISP2). I've defined…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • SFOS 20 IPV6 over PPPoE

    CA VAN LOGGERENBERG​
    CA VAN LOGGERENBERG​
    When will ipv6 be supported over PPPoE ? When I use any other router / firewall I am able to get IPv6 over PPPoE just not via Sophos
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • A phone is receiving ip address of the firewall when it connects to the network

    Anesu Dangarembwa
    Anesu Dangarembwa
    Good day We have an XG 35 ON VERSION 20.0.1 There is a phone that is connecting to the network.. and when it connects the network it is getting 192.168.10.1 which is the ip addresss of the firewall .. Our DHCP is the firewall , and the DHCP pool…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • IPv6 - possible to configure the link-local-address (to fe80::1 for example) ?

    dirkkotte
    dirkkotte
    In the IPv6 training, a manually configured IPv6 link-local address for the gateway was considered "best practice". fe80::1 would be a good choice... Is it possible to configure this with sophos firewall? ...or why this should not be done? thx in a…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Two VLAN on Same Server

    haidar salauroo
    haidar salauroo
    Hi, here is my setup, i have 2 VLAN ( 20 and 30 ) and both have DHCP enabled, and both have similar setting. VLAN is supposed to be used for Administration purposes and VLAN 30 for production traffic. VLAN 20 does not have access to Internet…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • LAG (LACP) Details & Statistics ?

    dirkkotte
    dirkkotte
    Hi all, Is it possible to got interface- & error details for a LACP-connection? Thx Dirk
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • From internet to DMZ

    Gino Pino
    Gino Pino
    Hello, I'm reconfiguring my fw (latest OS version), changing the zone and IP of my reverse proxy, from LAN to DMZ. Externally I'm able to reach my web sites with the RP on LAN, but if I change the zone and internal IP in firewall rule and NAT rules…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • two DHCP reservations messing up client gateway and DHCP options

    LHerzog
    LHerzog
    I noticed a strange mixing of DHCP settings when having 2 reservations for one client MAC address. console> system dhcp static-entry-scope show global I have a VLAN on the XGS lets say VLAN10 Net: 10.1.2.0/24 GW: 10.1.2.1 On that VLAN is a XGS DHCP…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • dhcpd_eve+ ??

    Sofos network
    Sofos network
    Hi all I have performance problems with the xg86w, the cpu sometimes reaches 100% the top command gives the following result: Thanks you.
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • RED60 with VLANs and DHCP Server - DNS Server IP wrong after Firewall Upgrade

    LHerzog
    LHerzog
    I've got a Site connected with RED60 The RED itself uses a single IP Subnet /31 IP Address and has 4 VLAN with /26 Subnets attached. In the Mgmt VLAN are Sophos APX Accesspoints connecting to Central. That setup was running up and fine for years…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • WAN link manager useless when using BGP?

    Sophos User5928
    Sophos User5928
    We are using BGP as the routing protocol to our ISP who provides us with two indepent WAN links and gateways which we can use as active/active or active/backup as we like. It seems that any setting in the Routing -> Gateway section of SFOS and the corresponding…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • DNS change Automatically in Sophos Firewall

    itinfrastructure User
    itinfrastructure User
    Hi I have XGS4300 (SFOS 19.5.4 MR-4-Build71),DNS change Automatically in Sophos Firewall it can possible or not can you please guide how to resolve this issue.
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Phantom DDNS Alerts

    Brian1941
    Brian1941
    Hi, Starting yesterday, I've received a few dozen Central email alerts on DDNS issues. The first issue is I'm getting alerts for the DDNS configured in the XG-125w: " What happened: FQDN xxxxx in location xxxx LLC isn't resolving to a valid IP address…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How do I setup DNS over TLS?

    GodAtum
    GodAtum
    I am using Sophos Firewall SFOS 20.0.0 GA-Build222. How do I setup DNS over TLS (with Cloudflare)? I can't find any instructions on the Sophos help pages.
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Does bridging VLANs or VLANs on a bridge make a difference?

    Wayne Folta
    Wayne Folta
    I have an APX320 on Port1 of an XGS. The original setup was to first bridge Port1, PortF1, and Port4 onto a bridge, LAN_Bridge, and then have the AP send three of its SSIDs down VLANs and bridge the other SSID to its LAN (LAN_Bridge). So the VLANs (LAN_Bridge…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Bridge needs firewall rules, or not?

    Wayne Folta
    Wayne Folta
    I had our Sophos XG87 configured by our reseller when we bought it, since I knew nothing about how to do it properly. I've learned a lot and have changed quite a few things, but want to make a foundational change that will require destroying several things…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Cannot recreate VLAN after unbinding port

    Wolfgang Jacques
    Wolfgang Jacques
    Port 1 was configured for LAN Usage VLAN 20 was added to Port 1 Port 1 was then unbound, VLAN 20 went away. Created VLAN 2 on the (unbound) Port 1 Wanted to create VLAN 20 again and add to Port 1 as well Get message " Interface name exists.…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Expose WAN Link Status to SNMP.

    Sheldon Dickinson
    Sheldon Dickinson
    I've found a number posts requesting assistance with this, but it appears that no one has had a win. We have multiple sites, all which have multiple WANs configured. In some cases, it's Active/Backup, in others, we are load balancing multiple WANs …
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Dynamic DNS update cadence in 20.0?

    Wayne Folta
    Wayne Folta
    I could swear that back in the day (maybe 18.5 or 19) that DDNS updated every five or 10 minutes and you could see this in the logs. We were using Google -- which has now sold its business -- and have switched to Cloudflare, and I'm not seeing any updates…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • IPv6 enviroment on XGS

    Quallensaft
    Quallensaft
    Kinda stupid question: Is there any "how-to doc" to setup a simple IPv6 dual-stack enviroment on XGS? Maybe the "right and secure" way to implement from v4 only to dual-stack? Nothing special need, just that a IPv6 client can reach the WAN via IPv6..…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • XG bridge editing causes network to go down

    Daniel Fehrenbach
    Daniel Fehrenbach
    Hello, I have a bridged interface. Port 1, 4, and 8. VLANs 1, 10. the bridge is in the LAN zone. VLAN 10 supports nearly all traffic, VLAN 1 exists for a private wifi network that allows guests/vendors to use the internet, but prevents them from…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • WAN Link Manager - What does Manual activation of gateway look like?

    DavidSain
    DavidSain
    There is an option to set the gateway to be activated manually. Is the process just to login to the firewall and change it from backup to active or is there something that becomes apparent when there is a gateway failure? I checked this documentation…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Adding WAN interface removes active WAN interface from Default SNAT rule, taking network down

    DavidSain
    DavidSain
    Customer is installing a new ISP connection but will have the old one for a while as they have WAF to an internal server, and DNS pointing to current ISP PIP. Left Port2 configured as it was. WAN zone, with static IP info. Configured Port3 to be the new…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • XGS2100 - VLAN gateways

    André Pinto
    André Pinto
    Hello, Please some help understanding the following scenario: VLAN ID - 400 VLAN ID - 410 On the network with vlan ID 400 I can use the ip gateway from VLAN ID 410 and it works! Rules are applied correctly (from VLAN ID 400). This happens in all the…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Assistance with Sophos NGFW Configuration for Inter-VM Communication

    Arkadiusz Parafiniuk
    Arkadiusz Parafiniuk
    Hello, I'm kinda new to networking and I'm currently working on a network lab to enhance my understanding of firewall concepts. My setup consists of the following: Virtual Machines: Kali Linux VM (IP: 192. 168. 10. 128) Windows VM (IP: 192. 168…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>