First off I understand the security implications of enabling web admin access via WAN. I've added a Local services ACL exception rule to permit one IP to the WAN interface for SSH/HTTPS access, however I still cannot enable https on the WAN interface…
Hi Team,
I recently install FW on VMware but issue is the login web page is taking too long to load. Using ssh I can easily and quickly go to the device setting but managementip:4444 is taking too long(20-30mins) to load. I used all the browser but…
I am running Sophos XGS 19.5.2 MR-2-Build624 in an active / passive cluster. I have configured IPSec VPN for 150+ remote users. I have enabled MFA for all Users. I have a small 3rd line support team, but want to provide access to my servicedesk to administer…
We have multiple techs in our organization and I don't share the default ADMIN account with them. I have set them up with their own accounts. However, if they are ever troubleshooting the firewall with a SOPHOS Engineer, almost immediately the engineer…
Hi
I am using XG-115 firewall in my network. We got number of VLANs
Can someone help me in restricting access to the Web Interface (and Putty) of the Sophos Firewall from certain VLANs. For example, let's say I got VLAN1, VLAN2, VLAN3 and VLAN4…
after validation of the capchat, access denied to the webconsole.
The certificate is valid, the acls are well saved to allow access to the webconsol.
What is going on ?
Hello,
I can't find any information about how the services in Local service ACL work.
Is there a page that explains what all the Local service ACL services do? A table with every single service explained would be great.
SOPHOS markets their XGS product to network administrators, who are professionals in their field. These are expensive devices that owned by the customer, and should be up to the customer how they wish to deploy\configure\use them.
SOPHOS, however, is…
Hi everyone
So I have downloaded the sophos firewall did the setup in vmware. I did do the initial wizard setup. Then I got logged into my sophos firewall gui login page. I was busy setting up but I forgot to plug in my laptop so everything shutdown…
When managing firewalls at remote sites that have a small or overloaded WAN line, I notice, it takes a long time, until the captcha fully loads. The ammount of time depends on the WAN situation on the remote side and can take up to 30 seconds.
it looks…
Hi,
the primary node of our firewall last night decided to go out of service, the last thing we could see was a full /tmp partition:
At 2023-07-05 08:55 when logged in SSH to C420xxx9CF, it showed /tmp full: GMTLOG: could not write temporary statistics…
When using the webadmin portal of our Sophos XG, I had massive problems with the operation today. The problems had expressed themselves in the sense that there were either messages during use that the page could not be loaded or that the loading circle…
In many environments there is a strict requirement that each administrator has their own administrative user. However, since many logs can only be viewed via the console, every administrator has to know the access data for the admin user. Will it be possible…
Im using the Sohpos UTM Virtual Applicance MR2 Version .. I have noticed that despite creating a drop rule for all zones, networks and services, the ACL still stands in control and firewall rules take no effect, only if the LAN Access at ACL device access…
Hello,
today we had a strange situation on SFOS 19.5.1:
a VPN user logged in with wrong credentials several times.
In the XG log this was shown as VPN auth failure in log as expected. SFOS does not log the client IP for failed logins anymore,…
Hi,
I have just received an RMA replacement for a secondary unit that died and was part of a HA pair.
What are the steps that I need to replace this unit.
I am struggling to log on to it with admin/admin, is this the wrong logon?
I can see that…
Hi Folks,
We are facing a strange behavior when using IPSEC Tunnel Mode and SDWAN routing.
When using IPSEC Tunnel Mode thw access between Hosts (behind XG Firewall) from BO and HO it works as expected, but when I try access XG GUI from HO side via…
Hi - My sophos firewall not accessing from web GUI. Firmware updated and checked apache tomcat services, status is running. Beside this there is high device utilization as well.
Hi,
We are trying to implement local service ACL on LAN side but it's not working. After checking on community found multiple posts but none works. Below are the Drop all rule and ACL snaps:
Device Access:
Added another drop management portal…
I have been using SG135 UTM for 5 years and I decided to upgrade to XGS136. Just like in the UTM, I want the web admin certificate to be valid. I have made a locally signed self-certificate, installed and trusted but I'm still having issues above. I have…
Hello! I am needing to configure access to the Web Admin Console from a DNS Host. I managed to configure the Local service ACL exception rule on the WAN and I can enter from an external IP, but I can't find a way to allow a dyndns for example.
I have…