• [How To] Use /etc/crontab-static to assign SSL VPN users a static IP address in the adress pool

    Hi, I've searched for the solution for a long time and didn't find a way to make changes persistent regarding the IP address of Sophos SSL VPN users. If do NOT allow multiple CN from one user (certificate), you can force the UTM's OpenVPN daemon to…
  • DNS Suffix not applying for hosts on different IP ranges

    When users (even me) connect via the SSL VPN client there are certain webapps that will not load without the fqdn. Examples: https://app1 = Fine https://app2 = Not Fine https://app2.domain.local.com = Fine You can ping and tracert "app2" and it resolves…
  • SFTP freigeben für eine IP Adresse und nicht das komplette Netz

    Hallo an alle hier. Ich habe eine UTM9 hier und möchte für einen Rechner SFTP freigeben für eine Zieadresse. Der Rechner ist ein Windows Terminalserver. Als Protokoll habe ich SSH angegeben. Als Ziel habe ich den DNS Namen des Ziels angegeben. Wenn…
  • SG-330 Node2 Powers off during HA Replication

    Hello all, Having some issues with a pair of SG-330's running in HA Active-Passive mode. When I get Node2 powered on it stays on for about a minute, begins Synchronizing, and then powers off with seemingly no warning. When I power Node2 on without…
  • KISS (Stupid, Simple) DNS Configuration, DNS Issues, and Possible DNS Bug on UTM

    I have a basic DNS setup for a home UTM configuration. The UTM is the only DNS server and also the DHCP server. All internal devices have DNS configured with the UTM LAN address as their DNS server. DHCP is also configured to provide the UTM's LAN address…
  • Home Lizenz Einspielung auf Gebrauchte SG 230 nicht möglich

    Hallo Leute, ich habe eine Gebrauchte SG 230 bekommen und wollte die Home Lizenz einspielen aber dann kommt das: und bei myutm wenn ich einen neuen Schlüssel erstellen will kommt diese Frage: Ich habe jetzt schon den Herrn von dem ich…
  • open ports for Tplink OC controller

    Hi Guys i have a Sophos UTM 9 SG310 within the network i have 7 Reds connected and each Red has TPLink access point, I can ping and reach these access points via cmd and web browser. but the hardware controller which is a TPLink OC 200 cannot see…
  • Sophos UTM Udemy Course

    I think what we all were thinking, finished my Sophos UTM Udemy course, thanks for all of your suppor without this community, it wouldn't be easy as much as it is now, I just wanna thank the Sophs Community for your support. If you wanna take a look…
  • Sophos UTM 9 - Block Specified URL on Network, Whitelist MAC Addresses

    Hello all, I have a Sophos SG 330 with UTM 9 and am trying to block access to a url ex. https://www.domain.com/page while not blocking the any other page on said domain. That being said I also need to whitelist a few devices by MAC address or local…
  • Unable to Authenticate to Web Filter UTM9 Home

    I've enabled the User Portal for these users. When I call up HTTPS://[IP of UTM] , the user portal presents itself and I am able to log in under my account as well as the other profiles that I created. (This is good and works the way I think I should…
  • Use additional address as VLAN gateway

    I've got a primary LAN and a guest VLAN, and I want the guest VLAN to have a different external IP address. I've set the additional address up, as it can go through the same router as the primary one, but I can't see how I would tell the VLAN to use that…
  • LAG consisting of two REDs on UTM 9?

    Hi, in the LAG configuration tab of an UTM 9 also red-Interfaces are selectable for membership of a link aggregation group. So lets assume a branch office has two red devices each with a different uplink. Would linking those red interfaces really…
  • [Solved] SSL VPN - Authentication failure for all users

    Hello, all of our users can't connect via SSL VPN since yesterday afternoon. I tried the connection via the old SSL VPN Client and via the new Sophos Connect client. Both don't work. I tried it with a new config file from the UTM, no difference. …
  • SD-RED20 behind UTM is local online, but without Internet

    Hi, I want to use a SD-RED20 behind an UTM with UTM 9.711-5 to connect a small office to headquarter. The connection from the SD-RED20 is established and working fine, for the local networks (few VLANs, split with a aruba, because the SD-20 can…
  • Block Traffic for Userportal, Webadmin, SMTP to specific Sophos additional address

    Hello, Sophos Services (Webadmin, Userportal, SMTP and so on) are on every Sophos IP address. But i need to disable or block every of thiis Services to spacific additional address. I try to create a Firewallrule and a NAT Sinkhole, but booth doesn…
  • SG 430 (Home Licence) Crashing/Freezing

    Hi, I have a second hand SG 430, running with a home licence. Firmware version = 9.711-5. It has been running for over a year with no issues. However, since the beginning of May, it has crashed/frozen 3 times. (see attached picture of hardware usage…
  • UTM In & Out Traffic

    Hello, Today i found something weird on my UTM logs, the client downloaded some files from Internet and i see the the traffic it show opposite direction, the download content should appear as Inbound traffic but below screenshot show totally wrong.…
  • Sophos Connect on macOS: Failure import connection

    Hi all, I updated our virtual test-UTM to the latest V9.711 and tried the new Sophos Connect client on macOS because we have a few customers with Macs. When importing the config-file (.ovpn) from the user-portal I get this error (my translation):…
  • Convert existing stand alone UTM to HA on AWS

    Hello, We currently have an UTM deployed in AWS VPC which we would like to convert to HA (cold standby). We are not keen to using either the cloud formation template or the conversion tool for the following reasons: - conversion tool makes the current…
  • In need of help! Vpn Site to Site

    Hello! I'm currently using Sophos UTM asg and i'm in need of help for two problems. (I really hope i can get answers as-soon as possible, please i would be very grateful) After doing web-filtring and vpn l2tp, i'm trying to make a vpn site-to-site.…
  • In need of help!

    Hello! I'm currently using Sophos UTM asg and i'm in need of help for two problems. (I really hope i can get answers as-soon as possible, please i would be very grateful) After doing web-filtring and vpn l2tp, i'm trying to make a vpn site-to-site.…
  • UTM Up2date 9.711 released

    We've just released SG UTM version 9.711. This release follows very quickly after 9.710 as it contains some important vulnerability fixes. We recommend that even if you only recently upgraded to 9.710, you should apply this fix as soon as possible. …
  • turksat-xml-rpc-proxy - what is it?

    May I know what this module is for? ep-confd-turksat-xml-rpc-proxy-9.70-1.g0916652.rb2.i686.rpm from latest release notes: Up2Date 9.710001 package description: Remarks: System will be rebooted Configuration will be upgraded News: Maintenance…
  • Overruns on Eth0 with vlans

    Not sure at what point this started happening, but users reported slow down with remote desktop sessions when a large burst of traffic from other vlans is being forwarded on other networks. The problem interface is Eth0 where we have vlans feeding into…
  • I Need Help Opening 2 Ports for one APP on a single workstation

    Newbie question. I am running Sophos Home UTM 9 software appliance on a server I built. I have an app running on a single workstation that needs to communicated in and out on ports 4000 and 4001. I set up the following rules but it doesn't seem to be…