Hi,
We have 2 types of IPsec and L2TP VPN users. one which have Intercept X on their systems and another which are normal users without Intercept X. Now we want to restrict users to access only from their specific machines. Like the users which have…
First, thank you, 2nd, sorry ;-)
I just got my XGS4500 setup, very basic default setups.
We use Unifi switches, we are migrating from a Meraki.
We have all our Wifi working, all the VLANs and whatnot - but our printers (for whatever reason…
Hello everyone, I joined the Sophos community, after having tried UTM9, I was delighted with its simplicity and functionality/security, so I decided to migrate my company's firewall system to XGS 136, I thought well if UTM is already good, this one should…
i would like to allow ip addresses from a company such as cloudflare. however, their ip addresses will be changing. i would like to allow their ASN number so that i don't need to keep track of their ip addresses changes.
is this possible?
Hi All,
We have a network firewall rule setup to allow traffic to a WAN destination.
However we can see in the logs that the traffic is getting blocked by the web filter component.
We have a user network rule further down the list that allows access…
(We are using XG550 active passive cluster with firmware 19.0.2)
Hi community,
today I have a strange problem again.
As SOPHOS told us not to use custom network objects for ipsec/sslvpn related firewall rules, I created a firewall ruleset based…
Hi,
when you attempt to delete a group and it is in a firewall rule you are disshown a message advising the that group exists in firewall rules or policies. If the group is in a SSL/TLS rule you are shown a message cannot be deleted, which is not very…
Hi,
I am facing a problem with the LAN zone attached to multiple interfaces. FW: SFOS 19.5.2 MR-2-Build624
Setup: Port1: LAN (192.168.30.254/255.255.255.0) Port2: WAN Port3: LAN (192.168.32.254 /255.255.255.0) I've created the following test rule…
Hi
I am using XG-115 as my firewall and already got number of rules. I also have a couple of VLANs. I followed the below guidance given by Sophos tech support team.
The rule works well with individual hosts. but when I replace the individual host…
Hello,
I need your help for making chromecast work again on my LAN. I had to restrict the protocols on my LAN.
My current setup is: Sophos XG, all devices on the LAN are allowed to use: http, https, smtp, smtps, imap, ping:
As a result,…
SFOS 19.5.1 MR-1-Build278
I was checking the logs when I noticed this strange peculiarity, in the log, the "firewall rule" is actually the firewall ID #.
The log is showing that the firewall rule with the name "Allow outbound" is firewall rule 1,…
For user based firewall rules, how to match users - that is add users to authenticate in a database?
I added an "any" "any" rule to allow all traffic to pass through, but it does not work, any possible reason why?
Does sophios have any cli interface…
hi all,
got a DNAT like below, blanked the fields out due to privacy
do i need to change my inbound interface and outbound interface to the correct ISP as i have two ISPs, so it could be going out wrong ISP, or will it pick the right ISP to go out…
Hi All,
I am new to Sophos XG coming from pfsense and have to say I will be staying, great NGFW. I have a slight issue though, one which I am sure is simple to solve.
I have used the server access assistant (DNAT) to create a port forward rule from…
Hi,
I am using Sophos XG firewall with Airtel ISP static IP now, when I am configuring Sophos XGS firewall OS its not pinging gateway even. But i have tested with old sonicwall firewall its no issues, even Sophos UTM 9.0 has no issues like this, Kindly…
Hello all,
I have a little issue with some traffic internet traffic getting denied by my Sophos firewall but I couldn't understand why.
Example 1:
Some traffic from a internal computer to Internet doesn't match anything even if my Internet access…
Hi,
Our server connects remotely to get files from an FTP server.
The outbound connection goes fine, but then inbound connection to port 20 is blocked.
How to properly create a firewall/NAT rule for this?
This is what happens in firewall logs…
Hi,
is there any option to extend column Names in Rules and Policies section, so we can see full name of each rule, rule group ? We need to use filtering to make it clear, otherwise it is one big mess. How u guys workaround this lack of feature ?
Hello all,
I have created two new zones on my Sophos and would like to have communication between them. I have already created the firewall rule and selected zone 1 as source and zone 2 as destination.
Unfortunately I can not get there into the other…
Dear All,
Would like to seek for your help, i have the following firewall rule from Sophos 17.5, i would like to create the same rule in Sophos version 19.5, how do i create it under firewall rule + NAT rules for the following ? any help would be…
By default, the agent's port is 161 and the manager's port is 162, but many internet operators here in Brazil leave this port blocked, which makes it impossible to access the firewall's SNMP. How to change this default port?
HI,
if it possible to enable/disable firewall rules via cronjob. The customer wants certain firewall rules to be deactivated every evening, the rules are activated manually upon request.
I was able to do that on the SG, it was possible to turn on…
I'm trying to access an FTP server located in our Server Zone from our DMZ Zone (passive mode).
When the server initially responds from port 21 to the initial connection, the connection is being blocked by Sophos XG - "FTP-bounce attack" but I have…
Dear All,
I currenty running a virtual sophos FW in esxi with version 19.0.1 MR-1-Build365, and i already have another internet gateway which using palo alto, this sophos i want to act as Internet Proxy, in client computer its will need to have below…