• Timestamp in email messages

    Sometimes our ISP is causing us grief and there are connectivity problems. I have set up UTM to check connectivity by pinging global DNSes (like 1.1.1.1 or 8.8.8.8); the UTM also sends out emails whenever connectivity fails. Unfortunately, these emails…
  • DNS Issues Since 9.509-3

    So here is our current setup. Since we upgraded to 9.5.09-3 we have been having delays with DNS. In the Firewall logs I can see the DNS requests going out but the DNS in Windows sometimes comes back without results. I am testing right from the GDC server…
  • Sophos UTM 9 to have OpenSSH version and higher

    Our Sophos has been detected to have a security issue. Please see the listed threats provided by the Security Compliance Team. They have advised that OpenSSH 7.4 has been released to fix these. Is it possible to have the said OpenSSH Version? Threat1…
  • After HDD fill up on Node 2 variables messed up: "Successful WebAdmin login from $IP at $TIMESTAMP with username $USERNAME."

    Hello! Approximately one week after upgrading the PostgreSQL database to 64 Bit, we had a problem with Node2-passive (active/passive configuration) in HA. Node2 coredumped continuously, filling up the Hard Disk with the fast-growing kernel-log (50+…
  • AP55 not appearing on VLAN

    I have an SG310 and an AP55 Access Point. I have a switch with 3 VLANS: - VLAN 1 is the default / LAN - VLAN 150 is called Management - VLAN 30 is WiFi If I plug my AP55 Access Point into a switch port that is untagged on VLAN 1, the AP55 gets an…
  • Root partition is filling up

    Hello, as of lately one of our UTM9 duo's in HA are borking up. I tried to read through some articles that can be found here, but my limited knowledge about linux commands and i slightly different situation in the results with df / du commands make…
  • reverse proxy for jira servicedesk

    Hello, I am running UTM version 9.509-3 which supports reverse proxy. Also, I do not wish to change to XG as I have tried it and i really don't like it. It feels to me overcomplicated for no obvious reason. So I would like to achieve the following…
  • Locally generated traffic from sophos cli being dropped.

    Hello Forum, For some troubleshooting I want to generate traffic from the sophos UTM cli using nc or telnet, using the following commands. root#telnet 192.168.100.1 512 root#nc -zv 192.168.100.1 512 The traffic is however being dropped by the sophos…
  • Changing Public IP-adresses

    We using the UTM on a public IP-address block of 4 adresses. This IP-addresses are assinged to 1 interface (I call it interface1 for now) 1 address isthe default interface address and the others are addtional adresses. This interfaces also contains the…
  • When would be UTM 9.507 or UTM 9.6 released?

    Hi, when do you expect UTM 9.507 would be released? Do you think UTM would recieve mitigation against Meltdown and Spectre with the next updates? I hope a UTM 9.6 or 10 would be developed, what do you think? UTM hasn't got updates for more than…
  • Multipath rule by application

    Hi Can you setup a multipath rule by application somehow? Similar to what you can do with QoS on a interface. I want youtube and other streaming sites for music to send traffic over the 2nd internet connection. So far I have tried some DNS groups…
  • Is it worth upgrading UTM9.5 to XG

    Hi, we are currently discussing about migrating our Sophos UTM 9.5 to Sophos XG v17 Firewall. So could you recommend upgrading to XG under following demands on the Firewall? Good filtering of malicious Websites Good indentification of application…
  • User Portal - Changing Password with OTP enabled

    Appliance Details: SG210 9.505-4, OTP enabled for ALL facilities (including User Portal) Problem: Cant change my password in the User Portal I have OTP enabled for all facilities and when I try to change my password I always see something to the effect…
  • How to retrieve ACT KEY for SG105

    Hello to all, I cannot activate subscription on mySophos for sg105 because I do not have the ACT Key for this device. How can I activate the purchased FG1A3CSAA Subscription on this device? It is it possible to retrieve the ACT Key again?
  • Blocking an External IP address in Sophos UTM

    Hello all! So over the course of the last day or two, we've been experiencing network slowness when trying to access web or anything external. After taking a deeper look today at some logs, I noticed that we are experienced some what of a DDoS. IPS…
  • How do i get my Sophos Home UTM Setup?

    Basically, i installed Sophos UTM Home onto my UTM220, and followed the basic setup, however after this when i added extra Ethernet interfaces in "interfaces" they wouldn't work. To be honest i dont understand how to setup the firewall, and i need help…
  • UTM 9 Issue with Site to Site SSL VPN

    I am trying to connect SSL VPN from AWS VPC to SSL VPN (UTM) On-Prem Network. The SSL VPN client (on-prem UTM) is not able to connect to SSL VPN Server UTM. Its failing and trying to reconnect without any success. The SSL VPN has been configured on TCP…
  • Can I Hide token information in the userportal by default

    Hi, As Rookie in the UTM world I have a question. I setting up two-way notification with the one-time password option of the UTM. I have this working however I mis I possibility. All user has to login with the OTP optie and get there token QR code…
  • Medium Strength SSL Ciphers and accreditation

    Hi, We've recently had a PEN test. We're looking to achieve necessary accreditation for Cyber Security. One of the things that the PEN Test found was a vulnerability on the UTM's public WAN address and other systems that Sophos UTM is providing…
  • How can I get my hotspot login page to pop up when someone uses a voucher?

    As far as I can tell I have my hotspot definition configured correctly and it almost seems to work correctly except when someone enters the WLAN password from the hotspot voucher, their device doesn't get redirected to the Terms of Use page and they're…
  • Need help with handling VLANS and DHCP across multiple interfaces

    I have a server running UTM in Hyper V with 3 Interfaces. Interface 1: Goes to a modem for internet connection Interface 2: Goes to a Cisco Meraki 220 switch Interface 3: Virtual switch for other virtual machines running on the server I split…
  • HOW TO - Outlook Web Access + Exchange Autodiscover + Outlook Anywhere with only one domain name

    Hello I have a big problem I need to create publications for Outlook Web Access + Exchange Autodiscover + Outlook Anywhere with only one domain name I have certificate only with one name - mail.domain.com Can you help me with detailed manual?…
  • iOS Mail unable to send/receive

    When connected through UTM 9, my iOS devices are not able to send or receive mail with multiple providers (EG: Yahoo, Gmail and 50webs hosting). When on LTE network, everything works as expected. What do I need to do to fix this problem? Thanks…
  • Blocking Communication on the Same Network Unless Specified

    Hi, I just have a quick question surrounding communication on within the same network. I know that between different networks I have to define rules to allow communication e.g. if i want to RDP between VLAN 101 (10.10.1.1) and 102 (10.10.2.1) which…
  • UTM Up2Date 9.506 Released

    9.506 is released. Maybe we could use this thread for reporting successful updated system and maybe not so many bugs. Who wants to be first to update? :-)