• Firewall RMA. How can reconnect RED device

    Luc_GLLM
    Luc_GLLM
    Hi, I have a defective XGS2100, an RMA has been opened and a new product will be sent back to me. When it arrives I will do a configuration restore starting from the backup of the faulty one, but two questions arise: 1) I have 5 RED20 devices connected…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS Certifikates: Certificate authority: Invalid or not installed

    encar
    encar
    Hello, I want to replace an SG firewall with an XGS. I donwloaded the wildcard certificate (.pem) and the certificate of the CA from the SG and uploaded them on the XGS. Though the the wildcard certicicate doesn't trust the CA. How can i solve this…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Enabling HTTPS on Enterprise Applications

    Srikrishna Pothukuchi
    Srikrishna Pothukuchi
    Hi, We have one VMWare server protected by this Sophos firewall. All our enterprise web applications are hosted on this server. Now, after accessing these enterprise applications, even though they are passing through the firewall, we are getting…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Comodo Certificates

    Mark Smith7
    Mark Smith7
    Hi I cant find anything recent on this in the forums. Im looking to purchase a wildcard certificate for securing several things. Are there any issues i need to be aware of using either a comodo positivessl (cheaper) or essentialssl? I would…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS: Public SSL Certificate for user/admin portal

    Rimfire
    Rimfire
    XGS 136 and 19.x firmware. Didn't find universal info how to generate proper CSR and how to import the public SSL Certificate to XGS For Request / Subject name attributes: Common name: domain name or FQDN including the host name? For Request / Subject…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web protection

    Stuart James
    Stuart James
    If I upload a new certificate because it's just been renewed, and then select that certificate in an existing firewall rule for web protection, it automatically deletes all the domains I've associated and puts in the ones it's found in the certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • WEBSERVER AND WAF

    abdellah adil
    abdellah adil
    I have a local web server i would like to publish it so i can access it from outside via port 443 , i've already generated an ssl certificate and i would like to use it via Sophos FW . is it possible to do it via WAF and attach the new SSL certificate…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall SSL VPN - prevent users from seeing a certificate error

    Farhood Norouzizadeh
    Farhood Norouzizadeh
    Hi all, We have a Sophos XGS firewall and we have imported a self signed certificate from our organization to the firewall which is used for the admin console and user portal under Admin console and end-user interaction -> certificate. We have also…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ssl certificate ; this website is unsecure

    support support18
    support support18
    I HAVE A WEBSITE ON MY LOCAL SERVER 172.16.1.1 port 80 , and it's working when i try to access it from the internet but only with http ; when i choose https 443 it shows an eeror msg 'this webisite is unsecure click on link to proceed " ; so i brought…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Problem with a FAKE SSL certificate Sophos is creating!

    Science-Rite CBD
    Science-Rite CBD
    Hello, Is there a SSL expert in the house? I was on a PUBLIC WiFi AP yesterday and was shocked to find out my websites SSL from DigiCert was not used. In fact, the WiFi said that my SSL Certificate is coming from Sophos. Below I will display what…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Where are all the places in XG firewall to install Go Daddy SSL certificate for Exchange email server?

    Sean Rome
    Sean Rome
    Greetings everyone! This is my first time installing a renewed SSL certificate for our email server in our new XGS firewall. Where are all the places the new certificate needs to go? I've uploaded it in certificates. Applied it in email general…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Single SSL VPN profile for multiple sites

    Matt Dickens
    Matt Dickens
    Good Afternoon, We have recently performed a migration from Sophos UTM to Sophos XGS and I am currently working on re-instating the SSL VPN service for use by our third party support companies. We operate two DCs with services either 'homed' in a specific…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • In XG firewall where are all the places you install a renewed SSL certificate for an email server?

    Sean Rome
    Sean Rome
    Greetings everyone, In XG firewall, I need to install and configure a renewed SSL certificate from Go Daddy. We have an Exchange server on premise. I've uploaded it into certificates. Applied it in firewall HTTPS OWA SMTP rule. Applied it in email…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • The user opens the outlook prompt certificate alarm

    Hongbo Xia
    Hongbo Xia
    Our customer recently updated the windows system patch. After the update, open the Outlook client, and always pop up a certificate warning. As shown in the figure below, please help analyze the cause of this problem, whether it is related to XG Firewall…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG: Configure SSL Remote access client to site

    Marco Malatesta1
    Marco Malatesta1
    Hello, do you know if is possible to use a third party wildcard certificate to configure an SSL remote access on an XG firewall? Thank you in advance, Marco.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Automate replacement of Letsencrypt SSL on Sophos SFOS?

    jang430
    jang430
    I am currently using SFOS 19.5.1 MR-1-Build278. I am hosting Emby (similar to Plex, I used Plex as it is more popular) container on my Qnap NAS, being protected by WAF. I have my own domain name from Porkbun, and I was able to generate SSL (Letsencrypt…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG CA and latest macOS break web sites

    rfcat_vk
    rfcat_vk
    Hi foks, I am running v19.5.1 on the XG and macOS13.3 on the mac book pro and mc air. A couple of sites no longer work and the default is https even though I enter hrttp.If I use a hotspot the issue is not observed. I have a mac mini in which the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • expired Root CA "DigiCert SHA2 Secure Server CA"

    LHerzog
    LHerzog
    Noticed some issues today with some popular SSL sites (linkedin, live, . These issues existed for some days but no one complained. The traffic was scanned by TLS/DPI engine and the servers had certificates issued by "DigiCert SHA2 Secure Server CA"…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • HTTPS decryption: Some users cannot browse site: Certificate expired yesterday

    LHerzog
    LHerzog
    We're having a strange situation again after it happened last week already on our SFOS 19.0.1 XG430: Some users browse to a website that has no exceptions on our firewall for decryption. The browser (firefox or chrome) show an error that the site…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Uploaded Certificate in Sophos XG Firewall Showing Not trusted

    Sacombank Cambodia itsupport_sc
    Sacombank Cambodia itsupport_sc
    I uploaded the certificate in every format (.pem,.pfx,.Cer) but none of showing trusted and always showing RED (X) in trusted for certificate issued from Digicert website. Please assist me to fix on this issue at earliest. Please find the attached screenshot…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Your connection is not Private

    tstan
    tstan
    Hi, purchased an XGS2100 to replace our SG230 for our Public WiFi connection. The device is not on a domain and has its own internet connection. It is only used for members of the public to get access to the internet on their own personal devices…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • SSL-VPN switch from TCP to UDP

    Thomas Linnepe
    Thomas Linnepe
    Hi folks, we are currently in the rollout of SSL-VPN Configurations and noticed performance issues at users which are using LTE Internet connections with latency. So we want to improve performance by switching from tcp to udp at the sophos firewall…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • how to bypass SSL/TLS in SOPHOS XG

    Ahmad
    Ahmad
    hi, i have XG430 , created a firewall rule and selected with following web filtering checks: Block QUIC protocol Scan HTTP and Decrypted HTTPS Scan FTP for Malware Decrypt HTTP during web proxy filtering. SSL and TLS inspection is enabled when user…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Remote Access VPN - IPSEC with Certificate - connection export .scx file invalid - SFOS 19.5

    philbert
    philbert
    Remote Access VPN IPSEC with Authentication type certificate does still lead to invalid connection .scx file on SFOS 19.5.0 GA-Build197, SFOS 19.5.1 MR-1-Build278 and SFOS 19.5.2 MR-2-Build624 if the "Organization name" in the Certificate does contain…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Invalid Certificate

    Kharl Levinn laniton
    Kharl Levinn laniton
    I have been using SG135 UTM for 5 years and I decided to upgrade to XGS136. Just like in the UTM, I want the web admin certificate to be valid. I have made a locally signed self-certificate, installed and trusted but I'm still having issues above. I have…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>