Sophos Firewall Sizing Guide: Properly Dimensioning XGS
Sophos Firewall sizing is not just about the number of users. Key factors include bandwidth, TLS Inspection, IPS, VPN, HA, logging, and reserve …
Practical German Sophos Firewall guides for setup, hardening, VPN, network rules, licenses, updates, logs, and troubleshooting.
The articles are organised by typical admin tasks: select, set up, secure, publish, connect remotely, analyse, and restore.
Sizing, XGS selection, Base License, bundles, Air Gap, lifecycle, portals, and license operation.
Sophos Firewall sizing is not just about the number of users. Key factors include bandwidth, TLS Inspection, IPS, VPN, HA, logging, and reserve …
Sophos offers Standard and Xstream as appliance bundles. Avanet Epic Protection adds Email and Webserver Protection to Xstream.
The Base License is the foundation of Sophos Firewall, but it does not replace support or security subscriptions. Licence status, support, updates, HA …
How to activate a Sophos Firewall Subscription Key and check its licence status, assignment, and synchronization.
Air-gap operation on Sophos Firewall requires approval, license file, manual synchronization, pattern updates, and a clear operational routine.
Sophos Firewall datasheet values are comparative figures. Key factors include firewall, IMIX, IPS, NGFW, TLS Inspection, VPN, and reserves.
Hardware, virtual appliance, Software Appliance and Cloud Deployment differ in operation, HA, recovery, sizing and responsibilities.
Standalone and Auto Scaling on AWS have different licensing, interfaces, traffic directions, and operating boundaries.
Azure runs Sophos Firewall as a cloud appliance. The operating model, static NIC addresses, UDRs, and symmetric return paths are decisive.
This article explains XG End of Life, XG vs XGS differences, SFOS 21/22 limits and how to prepare migration to XGS cleanly.
Sophos lifecycle planning needs End-of-Sale, Last Renewal, End-of-Life, successor products and clear checks before renewal, migration or hardware …
Warranty, support contract and RMA must be checked separately for Sophos hardware: serial number, purchase date, lifecycle, contract and replacement …
SophosID, Central, Support Portal and firewall portals serve different purposes. Login, licensing, access and Remote Access are key considerations.
The serial number uniquely identifies a Sophos Firewall. It is needed for support, licensing, RMA, Central registration, HA and inventory.
For hardware replacement, plan the claim, license transfer, and configuration restore separately. This workflow transfers subscriptions in Sophos …
How to safely transfer a Sophos Firewall license and account assignment to another Central account.
Setup Wizard, Central connection, Active Directory, STAS, SATC, Device Access, and support access.
After the Setup Wizard, the firewall is accessible but not yet fully hardened. Following this, backup, firmware, Device Access, rules, and logs are …
An accurate firewall clock is essential for logs, MFA, certificates, VPNs, and schedules. This guide shows how to configure and verify the time …
A Sophos Firewall can operate locally but offers additional features for management, backups, reporting, and security with Sophos Central.
Active Directory provides users, groups and authentication for Sophos Firewall. LDAPS, search base, group import, Main Group and AD SSO matter.
Groups bundle user policies but do not replace access rules. Their source, order, main group, and support for multiple groups determine the result.
Sophos Firewall can authenticate users from generic LDAP directories. A secure connection, correct search attributes, and the right Default group are …
A local user needs more than a username and password. Group, authentication method, service, rule, MFA, and lifecycle must work together.
Guest accounts receive time-limited credentials. A restrictive group, clear validity, a tested Captive Portal, and clean offboarding are essential.
RADIUS connects Sophos Firewall to NPS, MFA systems or other identity services. Shared secret, services, groups, timeouts and tests matter.
TACACS+ centralizes password verification, but the SFOS administrator role remains local. A safe rollout requires a local emergency admin, a pilot …
RADIUS SSO creates user-to-IP mappings from accounting packets. The actual sender, Framed-IP-Address, Device Access, and a controlled rule test are …
Clientless Users assign an identity to a fixed IP without a login or agent. A stable address, narrow rules, and a real negative test are essential.
STAS maps AD logons to client IPs so Sophos Firewall can use user-based rules. This guide covers setup, testing and troubleshooting.
Client Authentication Agent signs a user directly in to the firewall. The TLS-protected agent path, correct authentication method, and a real test of …
SATC maps users on Remote Desktop Session Hosts to Sophos Firewall. Server Protection, registry, Device Access and Live Users matter.
Per-Connection AD SSO identifies multiple users behind one RDS IP for each proxy connection. This guide covers selection, setup, tests, and limits.
Sophos Endpoint sends the Windows domain identity through Security Heartbeat. The firewall validates it in AD and can apply user-based rules.
Chromebook SSO maps signed-in Google Workspace users to their IP addresses. The certificate, Device Access, two firewall rules, and the managed MV3 …
Map Entra groups or app roles to local administrator profiles. A tested emergency login, least privilege, and a negative access test are essential.
Personal admin accounts replace shared logins. Profiles, MFA, schedules, and login sources limit permissions and make changes traceable.
The login disclaimer is a compliance and notice feature. It needs approved wording, separate access controls, and genuine tests for sign-in, email, …
Device Access protects local firewall services. This guide covers narrow ACL exceptions, safe rollout, proxy and port-sharing pitfalls, and targeted …
Avanet support access is restricted to the agreed source and period. This guide covers WebAdmin, Local Service ACL, MFA, optional SSH, testing and …
Firewall rules, zones, interfaces, VLAN, NAT, DNS, DHCP, SD-WAN, NTP, and VoIP.
Zones define security areas, while interfaces connect networks. Clear assignments, restrictive Device Access and suitable firewall rules are …
Wi-Fi managed directly by SFOS requires the correct traffic assignment, a suitable client network, DHCP, firewall rules and assignment to an access …
An APX mesh extends an existing SFOS-managed wireless network without a network cable, but requires a wired root AP, one fixed common channel, and a …
A guided example for restricted guest access with vouchers and the simpler alternative using a daily password.
Clear host and service objects make firewall rules easier to understand. The key is choosing the right object type, destination port, and checking …
Captive Portal links a browser login to user rules. Device Access, DNS, authentication, HTTPS, and a clean acceptance test are essential.
Firewall rules are at the heart of Sophos Firewall. The key aspects are rule structure, order, scope, rule types, practical examples, testing and …
Schedules limit rules and policies to defined time windows. The schedule type, firewall time, rule order, and tests before and after switching are …
Access Time combines a recurring schedule with Allow or Deny. User identification, policy assignment, the AD main group, and boundary tests are …
Surfing quota limits consumed internet time, while network traffic quota limits data volume. Assignment, main group, logging, and View usage are …
A clear rule description explains its purpose, ownership and expiry date. Logs, the Rule ID and usage data then show whether the rule is still needed.
An alias IP adds an address to a physical interface. The provider path, NAT, Device Access, ARP, and a real traffic test are essential.
PPPoE only works when the provider device, VLAN, credentials, gateway, DNS, and firewall rule all match.
VLANs on Sophos Firewall need more than a VLAN ID: parent interface, switch tagging, zone, IP objects, DHCP, DNS, rules, NAT and tests must match.
A bridge connects interfaces at layer 2. The transparent or routed design, loop prevention, and a real test between members are decisive.
A breakout divides a fast QSFP port into two or four slower interfaces. The model, port mode, restart, and peer device must match exactly.
A practical workflow for selecting transceivers, configuring ports, and troubleshooting a missing or unstable SFP link.
After SFOS 22, bridge VLANs are particularly noticeable for traffic to or from the firewall. CLI VLAN tags, br0 interfaces and tests are important.
A LAG bundles two to four ports. The right bonding mode, safe migration, switch configuration, and real failover and load tests are essential.
Fail-to-Wire keeps the physical path open during power or hardware failure. Traffic then passes without firewall rules, scanning, or logs.
Proxy ARP answers ARP requests for an additional IPv4 address. Firewall rules, NAT, routing, and the return path remain separate checks.
Discover Mode analyzes mirrored network traffic without being inline. A clean SPAN port, separate management, and a clear boundary are essential: TAP …
FQDN hosts help with dynamic cloud and service destinations. Wildcard FQDNs are different because the firewall learns matching IP addresses from DNS …
A reproducible test shows whether rule order, matching, NAT, routing, user matching, or a security module affects the connection.
Captive Portal with Entra ID SSO maps local users through browser login. Redirect URI, Device Access, group matching, and logs are important.
Rule tests need clear test data and real events. Log Viewer, Policy Tester, Packet Capture, tcpdump, Central Reporting, and Syslog answer different …
IPv6 Prefix Delegation brings provider prefixes into internal networks. Key aspects include WAN configuration, Router Advertisement, rules, and …
SFOS 22 supports IPv6 for many core features, but not everywhere. Knowing the limits prevents design mistakes involving VPN, WAF, DNS, updates, and …
Router Advertisement provides IPv6 clients with a prefix, default gateway, and operating flags. A suitable /64, the correct DHCPv6 role, and a real …
NAT translates addresses or ports but does not allow traffic. Important are SNAT, DNAT, MASQ, PAT, loopback, reflexive rules and troubleshooting.
DNAT publishes internal services through public IP addresses or ports. Narrow source restrictions, matching firewall rules, NAT order, the post-NAT …
Configure DDNS for a dynamic public IPv4 address, test it externally and resolve common provider, NAT, Multi-WAN and Cloudflare issues.
A DNS host entry answers a fixed name directly on the firewall. The actual client resolver, TTL, reverse lookup, and deliberately limited WAN …
DNS Request Routes forward specific DNS queries to defined DNS servers. Key points are firewall as resolver, internal domains, reverse lookups, DNS …
Identify MTU and MSS issues with VPN, XFRM, SD-WAN, or PPPoE using DF tests, Packet Capture, and controlled changes.
A DHCP server on Sophos Firewall distributes IP addresses and the corresponding network settings. A clean address range, correct DNS settings and a …
A DHCPv6 server can distribute IPv6 addresses and additional parameters. Router advertisement, DUID, lease times and the real client test remain …
DHCP options distribute PXE, WDS, thin client, or RED parameters. WebAdmin, CLI fallbacks, and common error patterns are important.
DHCP Relay forwards client requests to a central DHCP server. The client interface, scope, return path, and correct IPsec variant are essential.
A static route sends a fixed destination network through a defined next hop. This example covers configuration, firewall access, testing and rollback.
A second WAN connection is initially active. For a true backup link, configure the gateway type, probe targets, activation and failback deliberately.
SD-WAN routes steer defined traffic flows through specific gateways. Narrow criteria, suitable NAT and testing with real traffic are essential.
RIP distributes IPv4 routes in small or existing networks. The decisive factors are RIPv2, narrow peer access, passive client interfaces, and real …
Configure OSPFv2 for IPv4 with an end-to-end example, advertise routes selectively, and verify neighbors; OSPFv3 is covered separately.
Set up BGP with a complete eBGP example, permit it selectively, and test it from Neighbor status through to actual packet flow.
Route precedence decides whether Static, SD-WAN or VPN takes priority. The SFOS version, competing routes and a prepared rollback are critical.
A static multicast route forwards the data stream from a known sender to fixed interfaces. The group, firewall rule, receiver join, and testing on …
PIM-SM dynamically connects multicast senders and receivers across multiple routers. The decisive factors are a reachable RP, correct unicast routes …
Explain missing OSPF or BGP prefixes after an SFOS 22 upgrade, identify the affected design, and plan a route-based XFRM target design.
A custom gateway combines a defined next hop with health checks and SD-WAN routing. Test status, rule, return path, and actual traffic separately.
A GRE tunnel encapsulates IP traffic between two fixed endpoints. Static WAN addresses, matching tunnel IPs, routes, rules, and tests of both the …
WebAdmin IP tunnels carry IPv6 over IPv4 or IPv4 over IPv6. The tunnel type, endpoint address family, route, and return path must all match.
Central creates route-based IPsec connections between multiple firewalls. Planning, conflict resolution, and local validation remain essential.
Two CLI switches extend SD-WAN to reply packets and firewall traffic. Narrow routes, real packet tests and a documented rollback are essential.
Sophos Firewall provides the gateway, DHCP, and rules; UniFi transports the VLAN. The parent interface, port roles, NAT, and clean tests are critical.
Cellular WAN is usually a backup link. Reliable 4G/5G failover depends on the SIM, APN, PIN, gateway, signal quality, SD-WAN checks, and failback …
Sophos Firewall is not a full-fledged NTP server, but can forward NTP requests to external or internal time servers via NAT.
Learn how to classify ipsec_route correctly, capture the initial state, and test a manual route with policy-based IPsec.
This guide explains the difference between application-based and rule-based Traffic Shaping, with specific example values and operational checks.
VoIP problems often arise from SIP ALG, UDP timeouts, NAT, RTP ports or routing. SIP/RTP analysis, capture and CLI testing are important.
Sophos Connect, SSL VPN, Entra ID SSO, IPsec, SD-RED, and VPN troubleshooting.
Sophos Connect with IPsec, Sophos Connect with SSL VPN, classic OpenVPN clients and ZTNA fit different remote access scenarios.
Practical guide to Sophos Connect with IPsec, RSA certificates, groups, DNS, MFA, firewall rules and secure profile deployment.
A .pro file automatically retrieves IPsec and SSL VPN profiles through the VPN portal. This guide explains its structure, secure deployment, GPO …
SSL VPN Remote Access only works cleanly when global settings, portal, policy, current profile, DNS, MFA, Device Access, firewall rules and routing …
First document failed VPN Portal logins, then limit them with ACLs, separate ports, Login Security, identity protection, and Threat Feeds.
Clientless SSL VPN provides individual RDP, SSH, or file server connections in the browser without opening a general network tunnel.
An existing legacy IPsec configuration blocks SFOS 22 MR1. This guide covers everything from the initial assessment to a tested replacement.
L2TP remains a compatibility option for native VPN clients. This guide covers secure SFOS 22 configuration, validation, and common failures.
Sophos Connect on Windows requires the right client version, profile, platform, MFA/SSO and rules. Then verify the connection, DNS and access.
Sophos Connect on macOS depends on the client version, Apple Silicon and Rosetta, the IPsec or SSL VPN profile, DNS, MFA and tested firewall rules.
Entra ID SSO connects Remote Access with OAuth 2.0, OpenID Connect, and Entra-MFA. Key elements include Redirect URIs, groups, and Device Access.
Sophos Connect updates affect VPN profiles, platforms, MFA, SSO, helpdesk and rollback. Version checks, pilots, profile tests and known issues matter.
SSL VPN with Sophos Connect on Windows needs a current OVPN profile, VPN Portal access, MFA, client version, DNS test, profile cleanup, and matching …
SSL VPN on macOS now often uses Sophos Connect instead of Tunnelblick. The OVPN profile, Apple Silicon/Rosetta, DNS, MFA and maintenance are key.
SSL VPN on iPhone and iPad uses an OpenVPN-compatible client. OVPN profile, VPN Portal, MFA, DNS and firewall rules are important.
SSL VPN on Android requires an OpenVPN client, a current OVPN profile, VPN portal access, MFA, DNS tests, firewall rules, and device-change handling.
On Linux, SSL VPN with OpenVPN is the documented path. Sophos Connect is unavailable, and NetworkManager-strongSwan is incompatible because of …
A missing .ovpn file has different causes than a 0-byte download. This process separates policy, user, certificate, and system errors.
The old Sophos SSL VPN Client is EOL and incompatible from SFOS 20.0 MR1. Migrate its profile and startup safely to Sophos Connect.
SSL Site-to-Site connects two Sophos Firewalls in a client-server model. Roles, global SSL VPN settings, networks, APC import, rules and tests must …
This guide explains every important IPsec profile field and shows a modern and a compatible baseline for Site-to-Site VPNs.
Site-to-Site IPsec requires clear networks, profiles, gateway types, IDs, rules, routing, NAT and acceptance tests. Choose route-based or policy-based …
Two tested IPsec tunnels form a prioritized failover group. This guide explains selection, monitoring, failback, logs, and acceptance testing.
Azure Site-to-Site VPN needs Local Network Gateway, Virtual Network Gateway, matching IPsec/IKE parameters, Sophos XFRM, routes and firewall rules.
A branch full tunnel requires Any selectors, VPN before Static before SD-WAN, three targeted rules, MASQ, and a clear system-traffic decision.
AWS Site-to-Site VPN needs a customer gateway, target gateway, two tunnels, matching IPsec settings, routing and validation on both sides.
Certificate-based IPsec replaces the shared PSK with mutual trust. CA exchange, Certificate ID, peer certificate, rules and a planned renewal test are …
Overlapping IPsec networks require unique translated networks on both sides. Policy-based, route-based with selectors and Any-to-Any use different NAT …
One virtual address remains stable for the remote site while DNAT distributes new connections across multiple internal servers.
Two any-to-any tunnels use separate XFRM paths. Monitored gateways and static routes determine primary, backup, and failback behavior.
A clear diagnostic path for IPsec problems: first tunnel establishment and the Child SA, then rules, NAT, routing, the return path, and packet flow.
set vpn contains global advanced settings. This guide explains their effect, risk, baseline, and controlled testing on SFOS 22.
This guide distinguishes rekeying from idle timeouts and network faults and shows how to safely adjust a custom IPsec profile.
Sophos SD-RED connects remote sites to the firewall. This guide covers setup, performance tests, 802.3az, Tunnel compression, and common issues.
The RED mode determines the gateway, DHCP, internet path, and central control. This guide helps with the choice and shows safe functional tests.
Two Sophos Firewalls can connect through a Site-to-Site RED tunnel without RED hardware. This guide covers setup, security, and validation.
MFA, TLS Inspection, WAF, Threat Feeds, IPS, Web Protection, NDR, DNS Protection, and hardening.
FIPS mode enforces FIPS-compliant cryptography, but enabling it resets the firewall completely to factory settings.
Hardening reduces the attack surface of Sophos Firewall. Key areas are management access, MFA, updates, published services, threat feeds, logging and …
LINCE mode restricts cryptography and restarts SSH. It doesn't automatically prove that the installed SFOS build is certified.
This guide classifies all 31 Health Check findings by real risk, operational value, and optional Sophos services.
Practical guide to Sophos OTP, RADIUS and Entra SSO with a pilot group, app compatibility, password-plus-OTP, recovery and troubleshooting.
TLS Inspection increases visibility in encrypted connections, but needs CA distribution, clear rule order, DPI/Web Proxy decision, exclusions, tests …
A dedicated subordinate CA integrates Sophos Firewall with the internal PKI. The key points are a private key generated on the firewall, the correct …
TLS Inspection works without browser warnings only if clients trust the firewall CA. Important steps include download, distribution, and rollback.
XML API access on Sophos Firewall should only be allowed from defined management networks, automation systems, or integration hosts.
Bypass rules bypass the normal stateful firewall path. What is important is clear demarcation, tight networks, opposite directions, tests and …
Web Server Protection publishes HTTP and HTTPS applications as a reverse proxy. Key points are WAF or DNAT choice, DNS, certificate, web server …
Sophos Firewall can protect WAF-published web applications with MFA from SFOS 22. Version, Authentication Policy, token rollout, testing, and …
Sophos Firewall can obtain and renew Let's Encrypt certificates directly. HTTP validation, hosted address, port 80, supported services and monitoring …
How to import external certificates with the correct private key and CA chain into Sophos Firewall and assign them safely to the intended service.
Certificate Revocation Lists invalidate revoked certificates before expiry. The correct CA, a current CRL, and a real service test are essential.
Saving the Default CA creates a new trust anchor. Before doing so, certificates, VPN profiles, peer firewalls, and trusting clients must be fully …
Third-Party Threat Feeds bring known malicious IPs, domains, and URLs into Sophos Firewall. Feed quality, action, logging, and controlled operation …
Sophos X-Ops Threat Feeds compare outgoing traffic with known malicious destinations. Action, visibility, logging, and narrow exclusions are crucial.
Sophos MDR analysts can send customer-specific IoCs to the firewall in real time. Licensing, Central integration, the local action, logging, and a …
IPS needs a licence, global enablement, the right policy per firewall rule, signature awareness, logging, tests, performance checks and a …
Malware scanning only works when the firewall rule, scan engine, HTTPS decryption, exceptions, and tests are correctly aligned.
Custom IPS signatures detect your own network and application patterns. A narrow syntax, an observation-only pilot, correct IPS policy assignment, and …
Set ips changes the IPS engine firewall-wide. A baseline, focused test, and prepared rollback must precede fail-close, scan, or performance changes.
Web Protection requires an appropriate firewall rule, web policy, categories, user context, Web Exceptions, TLS visibility, QUIC decision, logging, …
DPI Engine and Web Proxy apply the same web policy on different traffic paths. The deciding factors are required proxy features, TLS decryption, and a …
URL groups collect domains for web policies and SSL/TLS inspection rules. A narrow domain scope, the correct rule, and a controlled negative test are …
NDR Essentials and NDR Active Threat Intelligence enhance Sophos Firewall with network detection. Key aspects include usage limits, operation, and …
Set up, test, and operate DNS Protection with Sophos Firewall, including internal DNS zones, endpoint limitations, and troubleshooting.
A Direct Web Proxy needs more than port 3128. A narrow pilot access, the correct rule, PAC deployment, and real proxy tests are essential.
The Device Console contains global settings for Web Proxy and Captive Portal. A baseline, focused test, and rollback come before any change.
IPv6-only clients reach IPv4 web destinations through Direct Web Proxy. Two separate rules and a genuine A-only test are essential.
Spoof Protection and DoS Settings harden against implausible sources and flooding. This guide explains WebAdmin thresholds, CLI policies, order, tests …
A parent proxy requires web proxy mode and different rules depending on its location. A narrow pilot, the correct NAT path, and real positive and …
service-param extends protocol inspection to additional ports but doesn't replace a firewall service or the matching web, TLS, or mail policy.
Country blocking, Black Hole DNAT, WAF Blocked countries, and Threat Feeds serve different purposes. Rule position, local services, and monitoring are …
Application Control identifies applications beyond simple ports. Important aspects include application filters, signatures, rule position, TLS …
Allow and log GenAI applications in a pilot group first, then block them selectively. This guide separates Application Control, Synchronized …
Zero-Day Protection analyses suspicious downloads and email attachments. Firewall rule, web and mail path, TLS visibility, reports, exceptions and …
This guide covers the mail flow and MX record, the MTA policy, validation, and troubleshooting without overlooking relay, TLS, or DKIM risks.
This guide connects the SPX template, trigger, password delivery, and Reply Portal into a controlled workflow for encrypted outbound email.
This guide combines the existing SMTP path with transparent proxy scanning, tightly scoped NAT and firewall rules, and reliable end-to-end validation.
Web Exceptions can bypass decryption, certificate validation, malware scanning, zero-day analysis, or policy checks. A narrow match, positive and …
This guide connects digest delivery with the user portal, quarantine area, and user assignment and shows how to test the complete release path.
This guide combines POP/IMAP settings, TLS trust, an optional scan policy, and a firewall rule into a controlled mail retrieval test.
Web categories and instant alerts assist in web policy control. Key aspects include usage, prerequisites, configuration, logging, and error patterns.
This guide shows how to correct a confirmed false positive with one tightly scoped email exception without disabling the remaining mail protection.
This guide connects Exchange Online and Sophos Firewall in a controlled bidirectional mail flow with tight relay access and reliable validation.
QUIC operates over UDP 80 and UDP 443. On the Sophos Firewall, it's important to understand when Block QUIC protocol is necessary and how to verify …
The appropriate Device Console commands for WebAdmin, User Portal, and global or VPN-specific settings.
Log Viewer, service logs, audit trail, SSH, CLI, packet capture, tcpdump, syslog, and SIEM.
For troubleshooting, know which Sophos Firewall service belongs to which module, which log file fits, and when Log Viewer, CTR, debug, or CLI is …
Log Viewer shows logged firewall decisions. This guide explains filters, fields, timing, limitations, and safe correlation.
If no new events appear in Log Viewer, first check filters, logging, and packet flow. Use the Garner workaround only on the exact matching build.
In cases of disruptions, VPN issues, or unclear firewall events, a support case requires clean logs, timestamps, and captures if necessary.
Configuration Audit shows which administrator changed supported firewall objects, when the change occurred, and what was modified.
SSH is a powerful support channel on Sophos Firewall. Device Access, ACL exceptions, public keys, host keys and control limits matter.
Essential CLI commands support log analysis, network checks, service status, and debug logging. A controlled workflow is what makes them useful.
Sophos Firewall needs its own outbound connections to Sophos services. Current FQDNs, DNS, NTP, routing, egress rules, and a targeted test for each …
Reserved ports remain blocked even when a service is unused. The SFOS 22 list prevents conflicts with portals, VPNs, and custom services.
SFOS loads several protocol helpers by default. Changes are global and require a status check, a test flow and an exact rollback.
Live Connections shows active consumers, while Connection List shows individual sessions. This guide explains filters, fields, limitations, and …
This guide shows how to capture a single flow in WebAdmin and identify where packets arrive, are forwarded, or are dropped.
tcpdump provides precise packet captures on the firewall. Key aspects include Advanced Shell, tight filters, PCAP files, interface comparison, support …
A successful server test doesn't prove that a user can sign in. This workflow separates the service, identity, group policy, and subsequent traffic …
Sophos Firewall uses the internal ID range through 65535 for users and groups. The specific ID shows whether authentication or VPN Portal problems are …
AD SSO can fail after certain upgrades to SFOS 22.0 GA. A log entry narrows down the issue before a targeted NASM rebuild.
A compact diagnostic workflow for drops: reproduce traffic, correlate Log Viewer and Packet Capture, then check rules, NAT, return path, and security …
Sophos Firewall may drop Accurate ECN as Invalid TCP reserved bit. Diagnosis, global CLI workaround, and a safe return to strict-policy on.
The Device Console groups global firewall parameters for packet inspection, TCP, UDP, and special paths. A baseline, narrow test, and rollback are …
The neighbor cache maps IPv4 and IPv6 addresses to MAC addresses. This guide shows how to check stale entries, relearn them, and safely use static …
The Wireless Controller CLI provides deep diagnostics. A baseline, one-change testing, data protection and complete rollback are essential.
After a firewall replacement, old ARP entries can block individual WAN or alias IP addresses. Packet Capture separates ARP from NAT and rule issues.
Missing Heartbeat means that the firewall continues to see traffic but no longer receives a matching Security Heartbeat. Scope, path and timing are …
Synchronized Application Control data should not be cleaned up using public PostgreSQL commands. This guide covers diagnosis, evidence collection, and …
iPerf3 measures throughput over a defined path. The test becomes meaningful with a baseline, clear direction, narrow firewall rule, and proper …
The sensor view and hardware log show host CPU, NPU, and fan values. Model limits, trends, load, rack temperature, and symptoms determine the …
sFlow makes traffic patterns and noticeable flows visible. Important aspects include Collector, Sampling, Interface Selection, Limits, and Operational …
Set up SNMPv3 securely on Sophos Firewall, test it with snmpget and snmpwalk, and correctly interpret the SFOS 22 hardware metrics.
NetFlow exports metadata from logged rule connections to an external collector. The key requirements are v5 compatibility, the UDP path, data …
The daily admin checklist combines current system status, trends, security events, and documented escalation without turning a single spike into a …
A speed test on the Sophos Firewall helps isolate WAN and client issues. Key aspects include SSH testing, WAN path, unit, test file, and …
The mail server and event selection are separate settings. Only a delivered test email and a real selected event confirm the complete alert path.
Data Anonymization protects usernames, IP, MAC, and email addresses in local logs and reports. Two authorizers and real export tests are essential.
Scheduled on-box reports send local analyses daily or weekly as a PDF. Report selection, mail transport, functional testing, and content review are …
Central Firewall Reporting transfers firewall logs to Sophos Central. Important aspects include log selection, retention, Report Hub, and syslog …
How to send the right Sophos Firewall logs reliably and securely to a Syslog server, SIEM, or SOC.
Backup, firmware, SFOS upgrades, task queue, services, Config Studio, reimage, SSD, HA, and RMA.
Backups require the file, password, Secure Storage Master Key, target version, management access, and restore compatibility. Essential before updates, …
A selective configuration import adds or overwrites objects, but isn't a restore. Dependencies, SSMK, compatibility, and real tests are decisive.
A compact go/no-go checklist for the upgrade path, recovery, HA, Central scheduling, and technical validation after a firmware update.
How to download and install a suitable SFOS image and verify the firewall with real functional tests after the restart.
SFLoader replaces corrupt firmware when WebAdmin is no longer accessible. This recovery path doesn't apply to XGS and requires a console, a matching …
Some older virtual Sophos Firewalls require a larger Primary Disk and adjusted partitions before SFOS 22.
The most important blockers and checks before an upgrade to SFOS 22.
Manage multiple Sophos Firewalls with one group policy without overwriting local configurations without control.
How to distinguish the two queues, handle errors safely, and then verify the change on the firewall.
SFOS 23 no longer supports the native eDirectory server type. This runbook covers target selection, parallel operation, group validation, cutover and …
Pattern updates keep protection signatures, engines and device firmware current. This guide covers automation, status, manual updates and …
Export complete or selective firewall configurations via the Sophos Central REST API, verify them, and import them in a controlled manner.
SFOS waits 3 seconds by default for a ready USB drive. Increase the value only for a confirmed detection problem and test again.
Restarting a service can recover an individual firewall module. The correct service, secure access and a real functional test are essential.
Config Studio makes firewall configurations readable, compares multiple versions and prepares changes or migrations.
The documented recovery method for physical appliances resets only the default admin password. Option 4, HA, and the follow-up checks are essential.
If only WebAdmin stops responding, tomcat and apache can be checked and restarted individually. Different requirements apply to HA.
After an unplanned restart, first preserve uptime, build, HA role, and logs. Then distinguish between software, load, power, hardware, and VM causes.
A factory reset removes the custom configuration but not all local data. Backup, recovery access, and the exact XGS model must be known first.
In failsafe mode, preserve the detected cause first. This runbook shows the diagnostic command, current VM requirements, and safe next steps.
A reimage fully overwrites the firewall. Before starting, backup, SSMK, installer image, restore compatibility, HA and post-checks matter.
The SMART endurance value helps assess SSD wear. Trends, symptoms, storage checks, HA nodes, and support data are decisive.
Storage warnings require root-cause analysis. /var, reports, event logs, troubleshooting logs, mail queue, warning thresholds and data retention are …
HA connects two Sophos Firewalls into a cluster. Important aspects include prerequisites, licensing, HA link, Monitored Ports, QuickHA, updates, RMA …
Custom cron jobs and startup scripts are not part of the normal SFOS operating model. This guide explains supported alternatives and a safe migration …
Since July 2026, Sophos Support Assistant guides troubleshooting and case creation. Good preparation remains essential for an efficient support case.
A clear Sophos RMA process: isolate the fault, secure data and backups, open a support case, check the replacement and meet the return deadline.
Special cases, older clients, and topics that do not fit neatly into the main areas.
Sophos Home Edition, XGS with Base License and Sophos Home suit different private scenarios. The CPU limit, benefits, limits and operation are …
L3 adoption requires TCP 8080 from the UniFi device to the controller and a valid Inform URL. DNS, SSH, and DHCP Option 43 are explained with …