• IP allowlist for WAF

    Electronic Repair & Logistics IT department
    Electronic Repair & Logistics IT department
    Using Web Server Protection, I want a web server to only be reachable from some IP lists or IP host groups. How can I achieve this? In Access permission , Allowed client networks , it seems that I can only choose individual IP hosts of networks. Am…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Block traffic to WAF correctly

    AquaNerd
    AquaNerd
    I'm struggling to block access to the WAF, I am trying to block all but Cloudflare IP ranges from accessing the WAF however there is still traffic hitting the WAF from non cloudflare IP's. If you are a non cloudflare IP then you get a forbidden page instead…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Port 80 and 443 open from external if using external IP address. Support says it goes to first rule that matches the port and ignores host name???

    AllanD
    AllanD
    We just had a PCI compliance scan and we failed because HTST wasn't enabled. Looking through everything HTST is enabled on all of our Web Server Protection rules including the default one. The PCI scanning company said the server replying is using apache…
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • WAF Exceptions not applying

    Stuart James
    Stuart James
    I'm getting an error on a URL with WAF for Static URL Hardening. I've added an exception but still getting the same error. What am I missing?
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Web Server Protection stopped working

    ChriZathens
    ChriZathens
    Hello guys! I have a home server running a few services on port 80 and 2-3 other ports I also have dyndns (3 hostnames) and have been using waf to connect to those 3 services without the need to enter a port in the url (There are also a couple of…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Seting up webserver protection with https -> http

    Geir Otto Olsen
    Geir Otto Olsen
    Hi, I would like to setup a Webserver protection using the WebServer and HTTPS to the Sophos FW, but behind the Firewal, I want to use HTTP. Could anyone tell me how to setup that? I can see how to setup for HTTPS, but I am not sure how to send it using…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • WAF wkth https not working

    Nazir Heravi
    Nazir Heravi
    Hallo everyone, I am facing with an issue in sophos XG with web server protection. I have created a WAF rule and redirect my alias ip to my webserver through HTTPS 443 select my certificate *company.com and add my webserver host my company.com but…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • WAF SSL Certificate Problem

    Nazir Ahmad Heravi
    Nazir Ahmad Heravi
    Dear All, I am facing with a Problem in sophos xg web server Protection, I have created all needed ruls and upload the ssl certificat to xg but in web application rule under the Host server when I select the HTTPS in the dropdaown menu I dont see me…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Exchange Enhanced Protection with SSL WAF

    gdmacmillan
    gdmacmillan
    So i know this topic has been discussed before but no one puts in a complete answer so going to ask it again. After enabling Exchang enhanced protection OWA externall breaks. I know this is due to the SSL offloading as this is mentioned in several posts…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Web Server Protection: Dependency Error

    Cedric Menzi1
    Cedric Menzi1
    Hello! I'm trying to setup a Web Server Protection Rule for my home automation system. I have a lot of other WAF rules which work perfectly. I'm only having trouble with this one rule, where I get the following error: I just can't get this rule…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Make specific URL with parameters available to the public and simplify it

    Thomas Schachtner
    Thomas Schachtner
    Hi there, we have an internal URL (like server1/.../access.php This link is designed to be accessed directly from the Internet and we would like to make it available to the public. But as this link is quite complicated and as it might reveal details…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Instructions on WAF Custom Authentication Form with example: Clarifying Documentation

    Itility
    Itility
    The WAF custom authentication form in the documentation is not that clear and required several rounds of testing to fix. Below I've added code that is easier to modify and quickly get up to speed without 30 minutes of troubleshooting and testing. I…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Sophos WAF

    Ilham Izzuddin Bin Sulaiman
    Ilham Izzuddin Bin Sulaiman
    Hello, I have a Peplink WAN gateway and a Sophos in the centre for routing from the core switch to the WAN.I have a problem: I cannot perform a waf for my webserver, which is hosted by peplink and the server are located at dmz, and my website is already…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Web server protection skip filter but no rule ID

    Carlo
    Carlo
    Hello, I have trouble configuring WAF rule for one specific web server/service When I try to access service from inside on my pc I get 403 [Sun Jan 07 19:40:08.983664 2024] [authz_core:error] [pid 22769:tid 140041007253248] [client 10.2.1.10:52039…
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • SFOS 20, Exchange 2019, WAF Active Sync

    Marco Walbert
    Marco Walbert
    Hi, i read a lot of posts about this Problem, but cant get it running. Made the WAF settings strictly by Sophos KB article, owa, outlook anywhere etc are running properly, but active sync isnt working. Log saus WAF Anomaly Inbound…
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • Does Web server protection (WAF) support HTTP/2 in SFOS v20?

    IT Racom
    IT Racom
    I've been reading some discussions about WAF support for HTTP/2 before. Is it available in the new SFOS v20? Or is it planned for some next MR?
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • WAF - Static URL Hardening error

    FFin
    FFin
    SFOS 19.5MR3 I'm getting multiple WAF-Logentrys with exact same URL (upper-/lowercase) - one request passes correctly the other one fails due to "Static URL Hardening - No Signature found". As it's same exact same URL it's probably not a configuration…
    • Answered
    • 11 months ago
    • Sophos Firewall
    • Discussions
  • WAF not working after Upgrade to SFOS 20.0

    EDV
    EDV
    We have updated our XGS3300 to SFOS 20.0 a few days ago. Since then our WAF ist not working. AH00526: Syntax error on line 106 of /cfs/waf/reverseproxy.conf: Invalid encrypted key AH00112: Warning: DocumentRoot [/sdisk/waffiles/1cf6480d9dcdd33a4319301e0d8ef22b…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos SFOS WAF Rules limit

    admin_idl
    admin_idl
    Hello, We use the Web Server Protection of Sophos XG Firewall and have now reached almost 60 WAF rules. This is also the maximum number of WAF rules. Is it possible to combine several URLs in one WAF rule and route them to different servers? WAF rule…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Is it possible to offload HTTPS on the Sophos fw and send plain HTTP to the real server ?

    Jochen Siers
    Jochen Siers
    Is it possible to decrypt HTTPs on the firewall and send plain HTTP to the webserver (without encrypting it again)? Thanks!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF & large files – how do you deal with it?

    dirkkotte
    dirkkotte
    Hi all, When AV or other protection features are enabled, we keep running into various problems while uploading large files. Sometimes the disk space (Temp=100%) seems to be the cause, sometimes other internal buffers. We have the requirement to allow…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SFOS 19.5.3 MR-3: Web Server Protected, Path-Specific routing - should this config work?

    gavo_nz
    gavo_nz
    Hi, I have a WAF rule configured for path-specific routing, however, the routes I am specifying are all to the same target web server, but with different restrictions. e.g. / - restricted to specific IP ranges, target sevrer1 /myapp/ - not restricted…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Order of domains in WAF rules

    Martijn Bouman
    Martijn Bouman
    XGS Firewall, WAF rules has 10 listed domains. What is the sort order based on for these domains? Whenever we delete one from say position 5, add a few new ones, then add the number 5 one again (we have saved and reopened the rule multiple times)…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WAF rules and IIS redirects with trailing slashes

    Martijn Bouman
    Martijn Bouman
    Situation. We have a WAF rule with several test sites in the domains list. Example below. test1.testurl.com test2.testurl.com test3.testurl.com test4.testurl.com These all point to one IIS. On the IIS these are all separate sites. When we…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • is it possible to combine SFOS WAF with the built in OTP / MFA function

    LHerzog
    LHerzog
    I found some old posts (>2y ago) about the XG WAF module not supporting MFA authentication for a webservice. Has this changed since? We want to use MFA before using on-prem Exchange OWA. Many internal users already have an Sophos MFA token and it…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>