Skip to content
Avanet

Setting Up and Testing Sophos Firewall Application Control

Application Control detects application traffic that cannot be meaningfully distinguished via ports alone. For example, a Sophos firewall can specifically allow or block remote control tools, tunneling applications, streaming or cloud storage. The hit is logged via the corresponding firewall rule; an application filter does not have its own action Log.

The core process is straightforward: create the filter under Applications > Application filter, assign it under Rules and policies > Firewall rules to the rule that actually matches, and then use a real client to verify the Rule ID, application, and action. A saved filter policy alone does not affect traffic.

Define the prerequisites and objective

Application Control belongs to the Web Protection Subscription. Check the license status under Administration > Licensing. Before configuring Application Control, determine:

  • the affected user or network area and its IPv4/IPv6 paths;
  • the application or group that should be initially monitored or blocked;
  • the firewall rule that is currently processing this traffic;
  • a test client, a reproducible test request, and the expected result;
  • the currently assigned Application Filter, rule position, and existing NAT assignment as the baseline for rollback.

Check signature updates under Backup & firmware > Pattern updates. They run automatically by default; Update pattern now updates all pattern definitions except the firmware patterns for AP and RED when needed. The status values Ready to install, Downloading, Success, and Failed help narrow down problems. Application signatures remain available without an active IPS license, whereas IPS signatures require both a suitable license and enabled IPS.

For the test rule, turn on Log firewall traffic. Logging applies to the firewall rule, not the Application Filter. If you only want to observe traffic, use a permissive filter and evaluate the detected applications before setting individual entries to Deny.

If the actual goal is prioritization or bandwidth limiting, supplement the filter with Configure Application Traffic Shaping on Sophos Firewall. Application-based SD-WAN routes use an Application Object instead; the process is covered in Set Up a Sophos Firewall SD-WAN Route with Gateway Failover.

Plan and create application filters

Under Applications > Application list you can see whether Sophos has its own signature and which category or risk it is currently assigned to. For the Name filter, contains, is, is not and does not contain are available. A catalog hit does not prove that the application is detected on your network; the client test later provides that evidence.

A fixed selection of individual applications is easily predictable. Criteria such as Risk, Category or the Classification available only for cloud applications, on the other hand, remain dynamic: new or reclassified signatures can also match in the future. Such rules need a documented owner and a review after pattern or classification changes.

The full path for a policy and its rule is:

Applications > Application filter > Add
Applications > Application filter > Edit policy > Add
  1. Assign a unique name under Add, for example Block_File_Transfer_Pilot.
  2. Choose a template. For targeted blocking, Allow All is a clear starting point; do not assume that every empty new policy automatically behaves this way.
  3. Save the policy, open it again and create a filter rule with Add.
  4. Either use Select Individual Application or use Select All to narrow down the hits via Application, Category, Risk, Characteristics, Technology, Classification or Smart Filter.
  5. Set Action to Allow or Deny.
  6. For example, under Schedule, select All the time or assign a suitable schedule.
  7. First save the filter rule and then the policy.

SFOS supplies the templates Allow All, Deny All, Block filter avoidance apps, Block generally unwanted apps, Block high risk (Risk Level 4 and 5) apps, Block peer to peer (P2P) networking apps and Block very high risk (Risk Level 5) apps, among others. A template is a starting point, not a ready-made standard. In particular, compare risk- and category-based rules with the applications your network requires before assigning them broadly.

Time-dependent rules require a suitable schedule. How to create it and check it against firewall time and fallback rules is described in Setting up Sophos Firewall Schedules for Rules and Policies.

Example: Block browser-based file transfers

The official example leaves other file transfer applications untouched and limits only browser-based transfers:

  1. Create the policy Block_File_Transfer_Pilot from Allow All and open it again.
  2. Create a rule with Add > Select All.
  3. Choose Category: File Transfer, Characteristics: Transfer files and Technology: Browser Based.
  4. Set Action: Deny and Schedule: All the time.
  5. Save the filter rule and then the policy.

This selection can also affect legitimate upload, collaboration, or backup processes. The pilot client should therefore test both a transfer to be blocked and an explicitly allowed business service from the same scope.

Assign filters to the correct firewall rule

Application Control only works in a firewall rule. For a new rule, the current path is:

Rules and policies > Firewall rules
> IPv4 or IPv6
> Add firewall rule
> New firewall rule
> Other security features
> Identify and control applications (App control)

For an existing rule, open Other security features directly and select the prepared application filter there. Log firewall traffic remains active for pilot and acceptance.

The rule must actually match the test client’s Source Zone, Source Network, Destination Zone, Destination Network, Services, and, where applicable, Match known users criteria. Firewall rules are evaluated from top to bottom; the first match ends the search. A more general rule above is therefore a more common cause than the Application Filter itself.

With a new Internet rule, the NAT path must also be correct. Sophos examples can generate a MASQ rule with Create linked NAT rule. In an existing environment, do not create a duplicate NAT rule preemptively; instead, check the effective SNAT/MASQ rule and note its NAT Rule ID.

IPv4 and IPv6 have their own rule paths. If the client uses both protocols, both are tested or the pilot is deliberately limited to one. The rule basics are explained Understanding and securely configuring Sophos firewall rules.

Prove the effect with live connections and Log Viewer

A robust test answers three separate questions: Which rule processes the flow, which application does SFOS detect, and which action is executed?

  1. Note the test client, source IP, user, time and destination.
  2. Optionally, run Reset data transfer count in the pilot rule’s options so that new traffic can be attributed more easily.
  3. Start the test connection and check the open session under Current activities > Live connections.
  4. Compare the application, Source IP, username, interfaces, source/destination ports, Firewall Rule ID and NAT Rule ID with the planned path.
  5. Open the Log viewer in the upper right corner of the web admin and filter it by source IP, user, destination, Rule ID and application.
  6. Run an expected block test and an allowed control test from the same scope.

A denied Application Filter hit appears as Content Filtering > Application > Denied. Allowed, detected traffic appears in the firewall log under Firewall > Firewall Rule > Allowed. For acceptance testing, document at least the Firewall Rule ID, Application Filter, application, category, risk, action, user, source, and destination.

Firewall sessions often only appear on the Connection Destroy event when SFOS closes the connection. A still open browser or streaming session can therefore already be visible under Live connections, although its final firewall log entry is missing. SSL/TLS connections are logged after the handshake completes and again when the connection closes.

Under Reports > Dashboards > Traffic dashboard > Allowed policies, you can also review the data transferred through allowing rules. However, the report does not replace the specific Rule ID and application test.

For Syslog or SIEM, field names differ by output format. The Central Reporting Format uses fields such as fw_rule_id, app_filter_policy_id, app_name, app_category, app_risk, app_resolved_by, qualifier, and status. In the Device Standard Format (Legacy), the corresponding fields include application_filter_policy, application_name, application_category, application_risk, and appresolvedby. app_resolved_by or appresolvedby distinguishes between values such as Signature, Proxy, and Synchronized Application Control (EAC).

Technical Application Filter and DPI events are written to ips.log; sig_upgrade.log and sigmigration.log help diagnose signature updates. For details about which services write to which logs, see Sophos Firewall Troubleshooting: Services and Logs. Packet capture can confirm IPs, ports, interfaces, and the packet path, but does not prove application classification. The combined diagnostic path is covered in Testing Sophos Firewall Rules with Log Viewer, Policy Test and Packet Capture.

Classify HTTPS, QUIC and Web exceptions

SFOS recognizes many signature-based applications even without full decryption. However, URL-based micro apps such as file transfers to Dropbox or Gmail require the decrypted URL in encrypted traffic. In the DPI path, a suitable rule is required for this under Rules and policies > SSL/TLS inspection rules. Scan HTTP and decrypted HTTPS enables malware scanning for already decrypted HTTPS, but does not turn on the decryption itself.

In the web proxy path, Decrypt HTTPS during web proxy filtering handles the decryption. An existing web policy does not prove that HTTPS is decrypted, nor that the same DPI rule applies. The controlled rollout is available in Introducing Sophos Firewall TLS Inspection correctly.

Block QUIC protocol discards outgoing UDP packets to ports 80 and 443 within the scope of the firewall rule so that clients fall back to a testable TCP path. SFOS selects the option by default when a Web policy is selected or Scan HTTP and decrypted HTTPS is activated. The web filter cannot scan QUIC, but this does not mean that QUIC bypasses every other firewall control. Block QUIC and HTTP/3 Correctly on Sophos Firewall describes the positive and negative tests.

If detection is unexpected, also check Web > Exceptions. A Web exception can skip decryption, malware/content scanning and policy checks and is valid in the DPI as well as in the proxy path depending on the selection. A wide exception can therefore remove the expected application context.

A firewall log entry with Allowed does not automatically prove that the user was permitted access through the web proxy: the firewall may pass the connection to the proxy before the Web filter logs it as Blocked. In such cases, review the firewall and web logs together.

Classify cloud applications

Under Applications > Cloud applications SFOS shows only allowed traffic and only applications for which traffic is available. The view can be filtered by date, Classification, Category and transferred bytes; Expand opens details. A missing entry therefore does not rule out a blocked attempt.

New cloud applications initially carry the classification new. After review, use Classify to assign sanctioned, unsanctioned, or tolerated. The new classification applies to new traffic and does not allow or block anything on its own. Only an Application Filter that uses this criterion and is assigned to a matching firewall rule implements the desired action.

Basic usage and byte data require firewall logging. Upload/download counters and file type details require HTTPS decryption; according to Sophos, a web policy not equal to None additionally improves accuracy and depth of detail. Some applications use their own transmission mechanisms, so that individual detail fields can still remain empty.

A prepared bandwidth policy can be assigned to a detected cloud application via Traffic shaping. This assignment does not replace the Application Filter or the firewall rule.

Special cases: online storage and Facebook videos

The official Google Drive example combines the Application Filter Block_GoogleDrive with the Web Policy BlockPersonalStorage. The filter is created from Allow All, searches for google drive with Smart Filter, and sets the selected applications to Deny and All the time. In Web > Policies, clear All web traffic for the narrow storage rule, search for personal via Add new item > Web category, and set the appropriate categories to Block HTTP and Block HTTPS. Both policies must be assigned to the same firewall rule that actually matches. Configure Web Protection on Sophos Firewall explains the policy mechanics.

For Facebook videos, use Select Individual Application in the Application Filter and select the matches for Facebook videos. For a custom web category, Sophos currently lists facebook.com/watch, facebook.com/reel, gateway.facebook.com, facebook.com/ajax, and facebook.com/stories, along with the keywords watch, reel, gateway, ajax, and videos. Treat these values as a version-specific starting point and review them before use because broad keywords may match other paths. Add this custom category to a blocking rule in the Web policy; the current Facebook procedure does not specify the action as explicitly as the storage example.

The Sophos example uses the web proxy, decrypts HTTPS, and blocks QUIC. Clients must therefore trust the Sophos Firewall CA. Do not switch an existing DPI environment solely for this special case; use a suitable SSL/TLS inspection rule instead. See Create Web Categories on Sophos Firewall for custom categories and Distribute the Sophos Firewall CA Certificate for HTTPS Scanning for CA distribution.

Use Synchronized Application Control in a targeted manner

Synchronized Application Control complements network detection with data from managed Sophos endpoints. In addition to the Web Protection Subscription, it requires Security Heartbeat, a Network Protection Subscription, a Sophos Fusion (formerly Sophos Central) account and a managed endpoint with a trial or full license.

The registration takes place at:

System > Sophos Central > Sophos Central registration > Register

After successful registration, SFOS automatically activates Security Heartbeat and Synchronized Application Control. If Security Heartbeat is turned off, Synchronized Application Control is also disabled; this is therefore not a narrowly scoped rollback for a single application.

For first-time use, after registration, check in Sophos Fusion (formerly Sophos Central) that Synchronized Application Control is turned on and enable it if necessary. The domain created on the firewall must match the domain selected on the endpoint.

Under Applications > Synchronized Application Control, search by name, path, category, or endpoint and expand an entry to view its occurrences. Sophos supports up to 15,000 applications. Since SFOS 20.0 MR1, SFOS stores only the five most recent occurrences of each application per endpoint.

When migrating to SFOS 21.0 or later, SFOS enables automated cleanup only if Synchronized Application Control (SAC) is turned on. The default retention period is twelve months. If a custom period was previously configured, it is retained. If SAC is turned off, both SAC and automated cleanup remain turned off. Cleanup also removes individually added applications from Application Filters. When migrating to SFOS 20.0 MR1 or later, SFOS deletes older occurrences; if automated cleanup fails because of insufficient storage space, Sophos directs you to Support.

New identifies new entries, Mapped identifies automatically assigned applications, and Customized identifies manually edited entries. The following actions are available under Manage > More options:

  • Customize: assign a clear name and an appropriate category, then select Apply;
  • Acknowledge: change the label from New to Customized without changing the name or category;
  • Hide and Show: hide an entry or show it again;
  • Delete: delete the application and remove it from any Application Filters that use it.

After Customize or Acknowledge, add the reviewed application to a new or existing Application Filter. Assign this filter to the firewall rule that actually matches. Then run a reproducible test flow and verify the expected Rule ID, application name, and action in the Log Viewer. Only after this pilot should you add the reviewed application to a production Allow or Deny filter rule.

A deleted entry reappears when an endpoint reports it again. Before Delete, therefore, check which filters use the entry; then run a new test flow and verify the expected Rule ID. For generative AI, Detect and control Generative AI with Sophos Firewall provides a dedicated pilot sequence.

Narrow down errors by symptom

  • The expected Rule ID is missing: Check rule order, source/destination, service, user match, and the IPv4/IPv6 path. Do not troubleshoot the Application Filter until the flow matches the expected rule.
  • No final firewall log entry: First search for the open session under Current activities > Live connections and end it in a controlled manner. Check logging and filter period in the Log Viewer.
  • The application remains unknown or generic: Check pattern status, Application list, HTTPS decryption, QUIC and Web Exceptions. Packet capture is used only to confirm the network path.
  • The block applies to too many services: Narrow the Risk, Category, Classification, or Smart Filter rule to individual applications or a smaller group. Then repeat the block test and the allowed control test.
  • After a pattern update, more is blocked: Check which new signature matches a dynamic criterion. Narrowly exclude a required application instead of switching off the entire filter.
  • The Log Viewer shows firewall Allowed, but the browser shows a block page: For proxy-processed traffic, also review the web log.
  • Cloud app details are missing: Check firewall logging, HTTPS decryption and Web Policy separately. Not every transmission method provides all the detail fields.
  • Facebook videos remain accessible despite the complete path: Check Rule ID, Application Filter, Web Policy, current category entries, QUIC, Decryption, Client CA and Web Exceptions. If the test remains reproducible, Sophos names support as the next escalation point.

Rollback and operation

Before the pilot, record the Application Filter, web policy, rule status, rule position, NAT assignment, TLS path, and exceptions. Rollback proceeds in this order:

  1. Deactivate a separate pilot rule or select the previous Application Filter or None again in the existing rule.
  2. Restore the documented rule position and only the NAT assignment that clearly belongs to the pilot configuration.
  3. Check new connections with the control client for the previous Rule ID and the expected behavior.
  4. Only then remove pilot filters or objects that are no longer needed. Do not delete shared filters, NAT rules, or Synchronized Application Control entries without first checking whether they are still in use.

In operation, the purpose, assigned firewall rules, dynamic criteria, allowed exceptions, owner, last change and review date are documented. For central evaluation, Enable Central Firewall Reporting and Set up Sophos Firewall Syslog and SIEM are suitable.

Change global classification only with Sophos support

The Application Filter of a firewall rule is not the global application classification in the Device Console. Sophos warns against changing these switches without instructions from Support. First, retrieve the current state without changing it:

system application_classification show
system application_classification microapp-discovery show

Global classification is on by default, while microapp-discovery is off by default. If Sophos Support specifies a change, record the previous state and the ticket. The documented switches are:

system application_classification on
system application_classification off
system application_classification microapp-discovery on
system application_classification microapp-discovery off

Turning on microapp-discovery restarts services and interrupts traffic. After an authorized change, you check both show outputs, a real application flow and the logs. The rollback restores the exact previous state: an earlier on is set with on, an earlier off with off and then checked again with show. For domain IOCs, the global classification also affects the context of third-party threat feeds.

Frequently asked questions

Where do you enable Application Control on Sophos Firewall?

You create or select the filter under Applications > Application filter and assign it under Other security features > Identify and control applications (App control) in the firewall rule that was actually hit.

Can you monitor applications without blocking them?

Yes. The Application Filter uses Allow, while Log firewall traffic is active in the firewall rule. After that, you check the application under Live connections, in the Log viewer and, if necessary, in Reports, before setting a narrow rule to Deny.

Does Application Control need TLS Inspection?

Not for every signature. URL-based Micro Apps and certain cloud details do, however, require decrypted HTTPS. The TLS or proxy rule that actually applies, along with QUIC, must therefore be part of the test.

Is Application Control the same as Web Filtering?

No. Application Control evaluates applications and protocols, web filtering URLs and web categories. Some official processes such as online storage or Facebook videos combine both levels.