This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Login with Captcha

I have just connected to an XG Firewall and as well as the user name and password and underneath is a captcha image with a box to type in response.

Haven't seen anything about that?

This thread was automatically locked due to age.
  • Hi  

    As an additional security measure, a captcha has been added to the XG Firewall admin and user portal on the WAN zone, for devices running SFOS v17.5 and later.

    For more information, please refer to the article -


    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Saw the original article and acted within 30 minutes of SMS message, but had not subsequently seen this information.


    My own XG is not providing the captch addiotin right now. Perhaps its being rolled out slowly

  • Having said that, my own Firewall was not affected.

    Hopefully, the captcha is being rolled out to all and noy just the affected systems?

  • [Updated - 5/7/2020 @ 4:50pm PDT]

    Hi All,

    Sophos added Captcha authentication to the admin and user portals on the WAN and VPN zones. This change only applies to XG Firewall v17.x and v18.x, except for XG85/XG85w devices. Any Cyberoam device that has upgraded to the XG Firewall firmware will not implement Captcha.

    This was implemented as an extra security defense against attackers attempting to script automated login attempts before customers had the opportunity to perform password resets; it’s also regarded as a best practice. The use of Captcha is currently not a policy-controlled option. Admins will see Captcha even if multi-factor authentication is enabled.

    Community Manager, Support & Services

    Support Videos | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.
  • FloSupport said:

    Sophos added Captcha authentication to the admin and user portals when they are exposed on the WAN interface.  

    As already mentioned by other users: these seems not to be the only criterias for adding Captcha authentication. I also get this on firewalls where neither admin nor user portal is exposed on WAN interfaces. So there must be some more reasons. 


    FloSupport said:

    This change only applies to XG Firewall v17.x and v18.x

    Generally or only on firewalls on which data exfiltration has been performed?

  • I for one, would be happy to see the captcha permanently regardless of exposure on WAN

    Just an extra step for security and ‘peace of mind’

Reply Children
  • I won't disagree with you, another security step is a good mesure....
    But, this wouldn't be done without advanced information.

    Regarding the Captcha JC Sophos,  you got an Android App and a IOS App for your Authenticator.
    I use it to access Sophos Central, it's too much to ask to do the same thing?