• Lets encrypt renew fail

    EinMarco_DE
    EinMarco_DE
    Hi everyone, We're using the integrated Let's Encrypt feature in SFOS V21. We've noticed some strange behavior when it comes to renewing certificates. When the firewall attempts to renew the certificate, it fails with the message: "Reason for failure…
    • 5 days ago
    • Sophos Firewall
    • Discussions
  • Renewing Expired Certificates

    haydenspence
    haydenspence
    Hello. Recently, a bunch of my locally-generated certificates have expired and I am having trouble finding a way to renew them. I am using the firewall's local CA to make certificates for WAF rules and the web-admin console. You'd think there would…
    • 5 days ago
    • Sophos Firewall
    • Discussions
  • Sophos XG Home V21 GA Lets Encrypt Certs not shown for Administration

    Frank Jepsen
    Frank Jepsen
    I successfully obtained 5 certificates from Lets Encrypt with th new V21 feature. I can use these in my web application firewall rules and they work fine. But in "Administration/Admin console and end-user interaction" only an uploaded wildcard certificate…
    • Answered
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall default Certificate Problem new deployment

    Gerd Rehders1
    Gerd Rehders1
    Hi, I'm facing a new issue: After deploying new Firewall the fresh instance cannot be synchronized with Central. Device keeps hanging on state connected The default certificate seems to be invalid (Namibia???) After editing the default authority and…
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN and Certificate Migration

    Clay Tsuhako
    Clay Tsuhako
    We currently use an SSL certificate from Digicert for IPSec VPN access for users. When migrating from an XG 210 to and XGS 2100 do I need to buy a new certificate or will the current certificate transfer over during the migration? Thank you.
    • Answered
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • certificate authority invalid or not installed

    SatyabrataB
    SatyabrataB
    Hi, we uploaded a certificate from our domain provider, but it's showing not trusted.
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Installing SSL certificate to all machines

    Anesu Dangarembwa
    Anesu Dangarembwa
    Good day I have client with XG 230, the They don't have an Active Directory, is there a way to install ssl appliance certificate to all machines.
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Appliance Certificate

    SophosNewby
    SophosNewby
    Does regenerating the Appliance Certificate affect any other access besides SSL VPN? This is my issue, we recently had our XG210 replaced and rebuilt the new unit with a backup. Prior to the firewall failure SSL VPN has been my goto setup for staff who…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Chrome OS no longer able to manually import Root CA Certificate

    tomrgsd
    tomrgsd
    Tried to add a certificate to an unmanaged Chromebook device with latest Chrome OS version (someone brought in their own device). Followed the steps as we have used for years. Download the CRT file and open Chrome Security settings and under manager certificates…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Certificate wrong after flushing device reports

    Diego Depiante
    Diego Depiante
    Dear Friends: I’ve been following this article because none of my reports were working. Sophos Firewall: No reports show After flushing the reports, it appears as though I never completed the configuration of my WAF certificates. So, I decided…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • How to import existing FW certificate?

    Vertical Technik
    Vertical Technik
    Good day all.. I have a no-name Firewall running with pfSense and FW Certificate. As my new Sophos XGS87 Firewall does not support pfSense I want to import the existing FW Certificate into Sophos. Problem: as per Sophos website I have to import…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • CA WebConsole not secure / https

    Bruno H Silva
    Bruno H Silva
    Dear collegues! When we access the Webconsole through the internal network https://xxx.xxx.xxx.xxx:port, the browser recognizes the certificate for https access as not secure. We are using the default Sophos certificate. How should I fix this problem…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Notification on Certificate expiration

    Niclas Lilie
    Niclas Lilie
    Hello, we have multiple environments of Sophos SG and XG Clusters. As we are not able to check every Cluster itself we automated a notification for WAF Certificate Expiration. On SG this is built-in but not so on the XG. I searched a little, and…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Update Certificates via API: Did I get it right?

    dtconnect
    dtconnect
    In 2018, Sophos integrated Let's Encrypt with their UTM series, leaving XG(S) users anticipating a similar feature. Many, including us, have turned to API solutions due to the lack of progress which is fine. However, the XG API feels less refined compared…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Replacing expired certificate

    Jaroslav Faldik
    Jaroslav Faldik
    Is there a simple way to replace an expired certificate without having to manually replace it with a valid one in all WAF rules and other places where it is used?
    • Answered
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Certificate renewal fail

    André Besteiro
    André Besteiro
    Hi, Our certificate for the site expires today and we've tried uploading a new one and it's imported but it's listed as untrusted. It's an Alpha SSL certificate and our service provider gave us the .csr and .key file. We copied the contents of the…
    • 9 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS Lets Encrypt HTTP Challenge

    Fritz Otlinghaus
    Fritz Otlinghaus
    Hey everybody, as we could not find any working solution in the discussion forum that does the Lets encrypt Process on the Sophos itself, we setup a process to run the whole thing on the sophos firewall it self. Our blog post https://blog.helsinki…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • XGS 2100: Certificate Authority: Invalid or Not Installed

    Graboid$
    Graboid$
    Hi Team, I uploaded a new PositiveSSL Cert (mail.company.com) for our Exchange On-premise email and I am getting an error "Certificate Authority: Invalid or Not Installed" We have a wildcard certificate (*.company.com) and it was recently renewed…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS136 admin console from LAN application certificate.

    DamienML
    DamienML
    Hi, What am I doing wrong? I have been administrating a new XGS 136 firewall and for some reason accessing the admin console on the LAN side has always reported the https certificate as not valid despite the fact the ApplianceCertificate is trusted…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Frase de acceso o clave previamente compartida

    Salud Darien
    Salud Darien
    buenas tardes quiero subir mi certificado ssl generado por godaddy.com y me pide una frase compartida. la cual no tengo idea donde se pone. me podrían ayudar. gracias adjunto imagen
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • touch /var/certcache/.clear_all_certs_on_reload - touch not a valid command

    Gavin Rodgers
    Gavin Rodgers
    Having issue registering firewall, guides show to clear certs, but im getting a notice saying the touch is not a valid command. Clear certs post Sophos Firewall: Purging expired certs from Sophos Firewall Rest certs post Registration loop thanks…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Our WMS is sending notification emails but they are bouncing on the firewall but there no logs on the firewall

    mulah
    mulah
    Our WMS is sending notification emails but they are bouncing on the firewall but there no logs on the firewall The vendor for the WMS system sent us the logs from their side and the certificate being displayed is saying Cyberoam and we are using sophos…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos (XG) Client Authentifikation Agent

    Ben@Network
    Ben@Network
    Hallo all, I am currently looking for a lean solution to build a rule per firewall that only applies to authenticated users. I have connected the firewall to the AD and installed the "Client Authentification Agent" on the (Windows) client. The user…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Unable to download Self-Signed CA certificate for SSL VPN Sophos Connect

    Werner Smit
    Werner Smit
    Good Day, I am trying to download our Self-Signed Certificate from the Firewall to deploy to all users to prevent users from seeing a certificate error when signing on to the Sophos Connect SSL VPN. There is no download button on the firewall what…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sectigo Certificate Status Not Trusted

    Trio Fandi
    Trio Fandi
    I have import both Certificate and Root CA in Certificate Authorities Menu. But Certificate status Not Trusted persist. I saw a weird description in subject of certificate appears in Sophos. There is a different description between Certificate Menu…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
>