Block compromised IP addresses with Sophos Endpoint
Sophos Central can prevent managed Windows and Linux devices from communicating with known compromised IP addresses. Internal or external IPv4 and IPv6 addresses and CIDR ranges can be blocked. macOS is not currently supported by this function.
Before blocking
Do not block an IP address across the tenant solely on an unconfirmed report. Check the source, observation period, direction, affected devices, possible shared-hosting use and expected business connections.
Management systems, Update Caches, Message Relays, Identity Services, DNS and other infrastructure are particularly critical. A protection function must not block the route through which it would need to be reversed or investigated.
Create an entry
Enable the function and create an entry under Global Settings > Protection and Remediation > Allow and Block > Network > Block compromised IP addresses.
Set the address or CIDR, expiry and a clear comment for each entry. The standard options are seven days, 30 days or no expiry. A permanent block requires an owner and regular review.
Up to 500 addresses or ranges can be managed individually in the interface. The Sophos Endpoint API can add up to 100 entries per operation. Help Desk users cannot use this function; an appropriate Central administrator role is required.
Pilot and verify the effect
- Use an exact IP rather than a broad CIDR where possible.
- Set a short expiry.
- Choose a representative Windows or Linux pilot.
- Test outbound and, where applicable, internal connectivity.
- Check Endpoint Events and the affected application.
- Only then broaden the scope.
An IP block does not end an active incident. Also isolate the affected device and investigate its processes, persistence, credentials and other destinations.
Removal and troubleshooting
To unblock the address, delete the entry and save the global list. The Endpoint then requires Central communication to receive the change.
If a block does not apply, check the platform, agent version, working Central communication, exact IP family, CIDR and Endpoint Events. For an unexpected outage, remove the specific entry first rather than permanently disabling the entire protection function.
Product boundary
This Endpoint IP list is not the same as Firewall blocking rules, DNS Protection or Active Threat Response for Sophos Switch and AP6. Each function has its own scope and logs.