• Why does the UTM have a strange delay after powering up before responding to PING and allowing network access?

    This is possibly a very silly question, but it's been on my mind for a while now. After a reboot, our UTM (SG 115) will, seemingly, boot up very quickly (at least the CLI will be quickly available). I guess this is due to the wonders of the SSD drive…
  • Best UTM 9.5 practise for UPS shutdown action

    We've got a UPS which is connected via USB to one of our Windows host servers. The UPS software has additionally been installed onto every other host server which uses the UPS. In the event of a power failure, the UPS will send shutdown commands to…
  • IPv6 Setup -- fe80 gateway assignment and NAT?

    Ok I've been working with IPv6 on the UTM.... It now passes all of the tests, but it shows my UTM external WAN address as my IPv6 address when I go to test-ipv6.com or ipv6-test.com -- it doesn't show my computer's address. On my computer, it shows…
  • High Load / High Disk Activity i/o causing http proxy (thus web access) to fail

    I am using UTM9 on a home network, using a low-end Dell desktop with 3GB RAM, Core2 Duo CPU. It has been working fine for many months, to protect our family's network. Last night, I installed some overdue UTM9 updates and ever since, I've been having…
  • Sophos UTM 9 HyperV Linux Integration Service - Data Exchange Files Location

    Hie. I want to exchange some information between the HyperV host (Windows 2012 R2) and a Sophos UTM 9 VM. Following is the output of "lsmod" sophos:/ # lsmod | grep hv hv_utils 13337 0 cn 12975 1 hv_utils hv_storvsc 17317 6 hv_netvsc 22297 0 hv_vmbus…
  • TPG Fibre 400 on a SG210

    I have just upgraded my internet to the TPG Fibre 400mbit service. However i can only get a maximum output on speedtest.net of 260mbit via my SG210. The Firewall is fully patched and uptodate. The service works as it have been tested directly…
  • IPSec Site2Site VPN Using Cisco C2800/C2900 and SG115 can't communicate eachother.

    Hi I setup Site-to-site VPN by IPSec using C2821 and SG115. It looks like to be connected from looking Site-to-site VPN Tunnel Status. but, it can't response by ping ,eachother. And ,this situation is reproducted when using C2921 instead of C2821. …
  • SG210 with Firmware: 9.411-3 most of the time at 90%+ CPU usage

    Hello, Since yesterday our Firewall is at 90%+ CPU usage. We already stopped the Services which generate the most but the Firewall is still at 90%+. Usually it was around 50-70% and worked without Problems. We didnt install anything new but the Problem…
  • DHCP VOIP Without VLAN

    Hello, We're in the beginning stages of rolling out IP phones and we want to use a different DHCP scope for phones as opposed to workstations. Our office is only roughly 40 users so I don't think VLANs are worth the effort so I wondering if someone with…
  • Needing to reboot the UTM

    For years, whenever I had a cable modem issue, and I called for tech support, I'd quietly chuckle when they would ask me to unplug the power to my router. However, a few weeks ago, that was what it took for my Internet to come back (Not literally removing…
  • Editing the linux back end for DNS in UTM9?

    OK, so we are located in a 3rd world country, and for various reasons that I won't go into, the local ISP DNS server is untrustworthy, so we set our DNS forwarders on our UTM9 and on our internal Windows 2008 servers to the Google Public DNS servers.…
  • SSL Remote Access Timers parameters

    Hi, we are using utm sophos model asg525 and we need to set timers parameters to SSL remote sessions, the only settings that i can see is under Remote Access > SSL > Advanced > Key Life Time, simple question, is this option to set the maximun duration…
  • Web Protection - nytimes.com

    Hi guys, I have many Sophos UTM (latest firmware) that report in Web Protection tab a lot of traffic to nytimes.com , but I'm sure no one is really looking at this website. Today a customer with 5 users is showing 22 GB of traffic to nytimes.com, that…
  • If The license is expire then the appliance should keep working?

    This is one of biggest drawback for Sophos end users it should not stop the services even the license is expired, such as Symantec anti-spam, Cisco ASA, BlueCoat Proxy etc, they continue working without disrupting the network except they will not get…
  • IPSec VPN does not work for IOS devices after upgrade to 9.411-3

    After upgrading to 9.411-3 IOS devices cannot connect via IPSec, if the configuration on the ISO device is deleted and configured again via remote access it works, but we dont like to bother our users reinstalling the VPN configuration... is there a way…
  • The Security Impact of HTTPS Interception

    Maybe interesting for someone: Sophos is listed on page 5 Fig. 3 Best regards Alex
  • How to find the ha advanced virtual_mac from command line?

    Hello, Does the command line "cc" or "/usr/locl/bin/confd-client.plx" have an option that allow to show the ha virtual mac? I really appreciate any help you can provide
  • SSL VPN with 2 Internet Connections and 2 Hostnames

    Good Morning Everybody, I need your help... I have 2 difference Internet Connections. One from A1 (slowly....) and a twice (faster,backup) LTE Connection. The UTM is configured with Upload Balancing beetween this two Uplinks. I also have a…
  • Dual WAN causes switch loop/broadcast storm

    Hello, I work for an ISP. We have a customer that is trying to use the Sophos UTM9 SG105 on our Network. They want to set this up between their current cable connection and the fiber connection from us. They uplink to us via a Mikrotik CloudSwitch…
  • Sophos UTM home use license 50 ip address. How do I renew license?

    I can't figure out how to renew my Sophos UTM home use license for 50 ips. I was able to create a new license file for unlimited but it has pretty much all the features I use at home disabled but unlimited ip's. I need to renew the ASG Home Use License…
  • Problem with ESXI 6 and UTM

    I've been running Sophos UTM in an ESXi 5.5 VM for a while with no problems. I need to move to a new server. The new server has ESXi 6u2, and I copied the VM over, configured the network cards (Configured as E1000), and fired it up. Everything seems to…
  • DNS Service fails every 30 minutes for ~60 seconds - SG105

    Hello, we have a SG105 that runs the DNS service. It forwards all requests that it cannot handle to the Google DNS servers 8.8.8.8 and 8.8.4.4. For some reason that I cannot figure out, the DNS service fails to forward requests every 30 minutes for…
  • tcptraceroute libnet_write failed? Attempted to write 40 bytes, only wrote -1

    Hi! I tend to use tcptraceroute a lot when troubleshooting link connectivity, with me being a newb and all. I noticed whenever I try to tcptraceroute to a greater than 1024 port, or a port number with more than 3 characters (eg 8443 instead of 443…
  • SSL VPN Client to use local IP in Home Office does not work properly

    Hello everyone, I am very concerned about an issue that I am experiencing with SSL VPN Clients. The idea is to simulate the SG210's local (public) IP-address on a couple of home offices. They shall not have access to the internal network, though…
  • Dropbox: KB 125491 - UTM: Decrypt and scan causes some applications to fail authentication

    As described in KB 125491 I created an exception to skip SSL scanning for dropbox. Didn't work. I had to skip authentication too. Then dropbox was working. Anybody sharing this experience? Setup is Proxy in standard mode with authentication against…