Skip to content
Avanet

Manage Windows Firewall with Sophos Central Endpoint

The Windows Firewall Policy in Sophos Central Endpoint manages the host firewall built into Windows. It has nothing to do with a Sophos Firewall appliance, its firewall rules or Central Firewall Management.

Sophos Central can monitor the state of Windows Firewall and other firewalls registered with Windows. In configuration mode, the policy sets the basic action for Domain, Private and Public profiles. Detailed exceptions remain Windows rules, GPOs or the responsibility of the deployed management system.

Three operating modes

ModeMeaning
DisabledSophos removes the Endpoint firewall component and stops monitoring
Monitor OnlySophos reports the state without changing profiles
Monitor and Configure Network ProfilesSophos monitors and applies the selected profile actions

Monitor Only is the default and the correct starting point for existing GPO or MDM management. Switching directly to Configure can combine local rules, Group Policy and third-party products into an unexpected result.

Actions per network profile

Domain, Private and Public offer three basic actions:

  • Block all: blocks profile network traffic without local exceptions.
  • Block with exceptions: blocks by default but honours local Windows Firewall exceptions.
  • Allow all: allows profile traffic.

For production clients, Block with exceptions is usually the only sensible enforcing baseline. Allow all largely removes the host firewall’s effect. Block all can interrupt management, authentication, printing, file storage and support access.

Windows, GPO and third-party products

The effective Windows Firewall configuration does not come from Sophos Central alone. Group Policy, local rules and other Windows-registered firewalls can affect it. Before migration, identify who currently owns the rule base.

When Sophos Central configures the profiles, the policy prevents changes to Windows Firewall through Windows Security Center. This is intentional but may change the previous helpdesk process. Detailed rules remain managed in the organisationally designated system.

Product boundary: This article covers only local Windows Firewall on an endpoint. Network firewall rules, NAT, VPN, Web Application Firewall and Sophos Firewall policies do not belong in this configuration.

If Sophos detects that Windows Group Policy manages the firewall, it does not apply the Sophos Central configuration. This prevents competing management, but the monitoring status continues to be reported.

Check My Environment > Computers & Servers > device > Summary > Windows Firewall. If Windows Group Policy shows Yes, a Configure policy not taking effect is expected and is not an MCS error.

Roll out safely

A new policy starts with Monitor Only. The pilot includes devices using Domain, Private and Public profiles plus a home-office client. Existing GPOs and local exceptions are then documented.

When switching to Monitor and Configure Network Profiles, control one profile first. Acceptance checks Central communication, DNS, DHCP, Active Directory, software distribution, Remote Support, printing and critical client-server connections.

Keep a fallback available, such as a higher-priority pilot policy or tested alternative management access. An endpoint whose Public profile blocks everything cannot reliably be repaired solely over that same network path.

Monitor another firewall

If another host firewall is registered with Windows Security Center, Sophos can monitor its state. This does not mean Sophos Central can configure its rule base. Green status confirms only the protection state reported by Windows, not the quality of all rules.

Troubleshooting

For unexpectedly blocked traffic, first check the active Windows network profile, effective Sophos policy and Windows Firewall rules. Then inspect GPO Resultant Set and registered security products. An apparent Sophos rule may actually come from a domain GPO.

If a user can no longer change Windows Firewall in Security Center, this is expected in Configure mode. If local change is required, adjust the operating model rather than manipulating the Endpoint agent.

If Central reports the wrong state, check Windows Security Center, service status and Events. A restart may be necessary after component changes. Do not “repair” the policy with a broad Threat Protection exclusion.

Installation ends with Could not set firewall auditing information

Older versions could fail with EnableFirewallAuditing: Error 0x80004005 and MSI error 1603. Sophos fixed the original defect in Endpoint Firewall 10.8.12.1. Use a current installer before attempting registry or auditing changes.

If it persists, record installer version, GPO and third-party firewall. Change the registry only for a current documented Sophos case with backup and Tamper Protection override; an old workaround is not a general repair.

Build Sophos Central Endpoint policies correctly explains policy assignment. Agent network access and proxy requirements are covered separately.

Frequently asked questions

Does this policy replace Sophos Firewall?

No. It manages local Windows Firewall on the endpoint. A Sophos Firewall appliance is a separate product with its own rule base.

What does Block with exceptions mean?

The profile blocks by default but permits traffic allowed through local or centrally supplied Windows Firewall exceptions.