Skip to content
Avanet

Configure and test Sophos Firewall malware scanning

Sophos Firewall malware scanning checks files in web traffic using the integrated antivirus engines. Enabling web filtering or selecting a Web Policy is not enough: The corresponding firewall rule must use Scan HTTP and decrypted HTTPS, and encrypted traffic must be decrypted before its content can be inspected.

This article focuses on downloads over HTTP and HTTPS. For categories, URL Groups, and user rules, see Web Protection with Web Policies. Zero-Day Protection can additionally analyse unknown files, while email traffic is protected separately through Mail Protection.

Clarify scope, prerequisites, and licenses

Classic malware scanning is bound to protocols and rules. Web downloads require Web Protection; the Base License alone does not include Web Malware Protection. Zero-Day Protection is a separate subscription that complements, rather than replaces, antivirus scanning. SMTP, POP3, and IMAP require Email Protection. Check the actual status and expiry date under Administration > Licensing; the required module must show Subscribed or Evaluating. An internet-connected firewall synchronizes licenses automatically every 24 hours. If the status appears stale, Administration > Licensing > Synchronize forces a refresh.

Meet these prerequisites before making changes:

  • Record the firewall rule, its Rule ID and position, and the current state of its scanning options.
  • For HTTPS, decide whether DPI Engine or Web Proxy performs decryption, and make sure the test client trusts the Signing CA in use.
  • Identify Web Exceptions and SSL/TLS Exclusion Rules that apply to the test path.
  • Prepare an isolated test client, a maintenance or pilot window, and access to Log Viewer.
  • Create a current backup under Backup and firmware > Backup and restore. Also record the few affected values so a rollback does not unnecessarily restore the entire configuration.

FTP and email use different controls from web traffic. Turn on Scan FTP for malware in the matching firewall rule; its global limit is Web > General settings > Maximum file scan size for FTP. For email, select the protocols actually used—IMAP, IMAPS, POP3, POP3S, SMTP, and/or SMTPS—at the end of the firewall rule; Add ports adds missing standard ports. MTA and Legacy policies, quarantine, and attachment actions are then managed under Email. The primary email scanner is under Email > General settings > Malware protection. These separate paths are delimited here; their complete setup belongs in the linked Mail Protection article.

File-type controls are not proof of a virus detection either. A Web Policy can allow or block downloads by file type, and an email policy can act on attachments. Only a correlated Malware log entry proves that the antivirus scanner detected the content.

What must work together for effective scanning

The result depends on several layers:

  • The correct firewall rule must actually match the client traffic.
  • Scan HTTP and decrypted HTTPS enables malware scanning for that rule path.
  • Web > General settings determines the engine, scanning behaviour, size limits, and how unscannable content is handled.
  • HTTPS content is only inspected when DPI or Web Proxy decrypts the connection.
  • Web Exceptions must not unintentionally bypass malware scanning.
  • QUIC must be controlled because QUIC traffic cannot be scanned like traditional HTTP and HTTPS.

A Web Policy and malware scanning perform different tasks. The Web Policy decides, for example, how to handle categories or file types. The antivirus scan inspects file content for known malware and PUAs. Malware scanning can therefore be active in a firewall rule even with Web policy: None. Conversely, selecting a Web Policy does not automatically mean that downloads are scanned for malware.

Choose single or dual engine

The primary antivirus engine is set under System services > Malware protection. Sophos Firewall uses Sophos and Avira; the selected Primary Engine scans by itself with Single engine and scans first with Dual engine.

The global selection for web traffic is located under:

Web > General settings > Malware and content scanning
  • Single engine: Uses only the Primary Engine. This requires fewer resources and offers the best performance. For Zero-Day Protection, Sophos must be the Primary Engine.
  • Dual engine: Uses the primary engine first and then the second engine. This increases detection coverage but requires more time and resources.

For normal client networks, Single engine with Sophos as Primary Engine is a reasonable starting point when throughput and latency are important. Dual engine is appropriate when maximum detection coverage has higher priority and the appliance can handle the additional load under real conditions. The decision should not be based only on data-sheet values: A pilot with typical downloads, video conferences, and software distribution shows the actual impact more reliably.

⚠️ Changing the Primary Engine or switching from Single to Dual has a global effect on matching scan paths. Before making a change, account for existing web, FTP, and mail policies as well as Zero-Day Protection, and document a rollback path. Changing the global primary antivirus engine may also change a locally specified antivirus engine. Review local engine selections after the change.

Control machine learning detection in the scan engine

SFOS 22 can enable machine learning, or ML, globally for the Sophos scan engine and then separately for feature groups. ML looks for suspicious patterns that may not yet exist in the signature database. It extends detection for new or fast-spreading threats, but also increases the risk of false positives.

First record the current state with the read-only command:

show scanengine

The documented defaults are ml_scan on globally, ml_web_detection off for Web Proxy and DPI Engine, ml_email_detection on for Email, and ml_legacy_detection off for WAF and FTP proxy. When global ml_scan is off, ML can’t be enabled effectively for the individual feature groups. The feature switches determine whether an ML detection can trigger a block action there.

The complete CLI syntax is:

set scanengine ml_scan <on|off>
set scanengine ml_web_detection <on|off>
set scanengine ml_email_detection <on|off>
set scanengine ml_legacy_detection <on|off>
set scanengine thread_count <1-128|default>

thread_count applies per scan engine. The range is 1 to 128; default calculates the number dynamically from the available CPUs. A fixed thread count isn’t adopted as general performance tuning. It requires reproducible scanner load, CPU and memory measurements, a throughput test, and usually specific support guidance. The older max_buffer_size option is deprecated and isn’t changed.

⚠️ ML may incorrectly block legitimate files or traffic, and ML detections generate telemetry for Sophos Labs. Activation, privacy, affected data paths, and the false-positive process are therefore clarified before rollout; disabling ML globally on suspicion is no cleaner than an unverified allow exception.

The pilot starts with exactly one feature group and a controlled client or mail flow. Compare show scanengine, policy, block action, Log Viewer, application result, CPU, and scan time before and after. EICAR confirms normal malware scanning but doesn’t prove ML detection of a new pattern. Rollback restores the values recorded with show scanengine and isn’t blindly equated with product defaults.

Define scanning behaviour

In addition to the engine, further protection decisions are configured under Web > General settings.

Unscannable content

Action on malware scan failure defines what happens to content that cannot be inspected completely. This can occur with encrypted or damaged archives and files nested too deeply. Sophos Firewall scans archives up to 16 compression levels.

Block offers stronger protection but can stop legitimate password-protected or defective files. Allow preserves the business process but permits uninspected content. Block is the safer starting point for normal client networks. If this disrupts a business application, investigate the specific file path before relaxing the global setting.

File sizes and streaming

Do not scan files larger than sets the maximum scan size for HTTP and HTTPS. Larger files are not scanned. For compressed files, the archive size counts, not the potential size after extraction. FTP has a separate limit under Maximum file scan size for FTP.

A small limit does not automatically improve security because it can allow large installers or archives to pass unscanned. A very high value, however, can increase download times and resource consumption. The value must therefore match software distribution, update packages, and appliance performance.

Under Web > General settings, open Advanced settings to access Scan audio and video files. Scan audio and video files extends scanning to media content but can impair streaming. Enable the option only when the protection requirement justifies the additional load and possible interruptions. After selecting the desired web scanning settings, click Apply to save the changes.

Handle PUAs

Block potentially unwanted applications detects programs that are not necessarily malware but may include adware, unwanted remote control, or risky system changes. Add an entry under Authorized PUAs only after checking the file, source, purpose, and owner. A blanket approval weakens protection for all matching scan paths.

Enable malware scanning in the firewall rule

The rule is located under:

Rules and policies > Firewall rules

For a typical client internet rule, check the following under Web filtering:

  1. Source zone and Source networks correspond to the client network.
  2. Destination zone is WAN, and the Services cover the intended web traffic.
  3. Log firewall traffic is enabled.
  4. Scan HTTP and decrypted HTTPS is enabled.
  5. Block QUIC protocol is enabled if web traffic should use the controlled TCP path.
  6. DPI or Web Proxy has been selected deliberately.
  7. Use Zero-day protection is additionally enabled only if unknown files should be analysed.

A compact rule example:

Rule name: LAN_USERS_WEB
Source zones: LAN
Source networks and devices: LAN_CLIENTS
Destination zones: WAN
Destination networks: Any
Services: HTTP, HTTPS
Web policy: LAN_STANDARD_WEB
Scan HTTP and decrypted HTTPS: On
Block QUIC protocol: On
Use web proxy instead of DPI engine: Off
Log firewall traffic: On

The example uses the DPI Engine. LAN_USERS_WEB, LAN_CLIENTS, and LAN_STANDARD_WEB are example names to replace with your own objects. For malware scanning alone, Web policy may also be None. Services should contain only the protocols you need; Any would be broader than necessary for this web example. A broader rule above LAN_USERS_WEB may process the traffic first, so Rule ID and rule order must always be part of acceptance testing. Understanding and building firewall rules correctly explains the fundamentals.

Complete HTTPS with DPI or Web Proxy

Scan HTTP and decrypted HTTPS does not decrypt HTTPS itself. The option only scans unencrypted HTTP and HTTPS content that another part of the configuration has already decrypted.

DPI Engine

With the DPI Engine, decryption is configured under:

Rules and policies > SSL/TLS inspection rules

A matching SSL/TLS inspection rule must apply to the test client and destination and use Action: Decrypt. Clients must trust the Signing CA in use. Roll out TLS Inspection step by step covers planning, the pilot, and exceptions; certificate distribution is explained in Install the CA certificate for HTTPS scanning.

Web Proxy

For the proxy path, enable Use web proxy instead of DPI engine and, for HTTPS, Decrypt HTTPS during web proxy filtering in the firewall rule. Under Web > General settings, the proxy can then scan in two modes:

  • Batch: Downloads the complete file to the firewall first and only passes it on after scanning. This provides stricter inspection but can noticeably delay downloads.
  • Real-time: Passes parts of the download onward but only completes the transfer after the content has been assessed as clean.

With Batch, the upstream download to the firewall can use the full bandwidth and affect other web requests. In the general proxy scanning path, Traffic Shaping is applied when content is passed to the browser in both Batch and Real-time; this is not a promise to limit that upstream batch download. Direct Web Proxy has an explicit exception: a Traffic Shaping Policy does not apply to that path. Before changing the scanning mode, document the previous value; use the same representative downloads to compare WAN utilisation, client download time, scan result and Rule ID. If a regression occurs, restore the previous scanning mode rather than changing the engine or policy at the same time.

The DPI Engine always operates in Real-time mode. Do not switch between Proxy and DPI merely because of one isolated issue, as their feature sets, ports, logs, and user behaviour differ.

The choice between Real-time DPI, Batch or Real-time proxy scanning, and the safe pilot change are covered in Choose DPI Engine or Web Proxy correctly.

Control exceptions and QUIC

A Web Exception can bypass Malware and content scanning. For matching traffic, this also automatically bypasses Zero-Day analysis. Exceptions should therefore have a narrow host or URL scope, a clear owner, and a review date.

QUIC, or HTTP/3, generally uses UDP 443. Sophos Firewall cannot scan this traffic like traditional web traffic. Block QUIC protocol blocks outbound UDP on ports 80 and 443 in the corresponding firewall rule so that compatible clients fall back to TCP and HTTPS. Background information and tests are available in Block QUIC and HTTP/3 correctly.

Test operation safely

A green Policy Test or an enabled checkbox does not prove that content is being inspected. The test must originate from a client behind the affected firewall rule; a download directly from the firewall checks a different traffic path.

To verify the Sophos Firewall web path, use the specific Anti-virus EICAR test action on the SophosTest page for Web Security. To test transport of the standardized test file independently of that test site, use one variant of the EICAR Anti-Malware Test File instead. EICAR is not real malware, but antivirus products deliberately detect it as if it were malware. Never introduce real malicious software into a production network, and do not open or execute the test file.

Practical procedure:

  1. Define an isolated test client and the expected firewall Rule ID. This test does not require a temporary allow exception. If endpoint protection acts first, do not disable it; treat the result as inconclusive for the firewall instead.
  2. Record the time, client IP, selected test URL, and expected scan path.
  3. Open the Firewall, SSL/TLS inspection, Web filter, and Malware modules in Log Viewer.
  4. For HTTPS, verify that the connection is actually processed with Decrypt.
  5. Run Anti-virus EICAR test on SophosTest or download exactly one EICAR variant. The expected result is for the firewall to interrupt the transfer before the download completes.
  6. Verify that the Malware log shows an antivirus detection for the same client, Rule ID, URL, and time.
  7. Close the test page and remove any partial or test file and browser-cache artifact according to the endpoint procedure; do not restore or execute a quarantined object. Revert temporary test settings and confirm with a normal download that web access still works.

A block page alone is not enough. The Web Policy, a file type rule, an endpoint product, or the category of the test site itself may also cause a block. The correlated Malware entry from the firewall is decisive. In Syslog, a web malware detection appears with log_type="Anti-Virus"; depending on the protocol, the components are HTTP or HTTPS, and the Subtype for a detection is Virus.

If Log Viewer does not clarify whether the local antivirus service is operating, its service log can additionally be observed in the Advanced Shell during a controlled test:

tail -f /log/avd.log

Press Ctrl+C to stop the display. avd.log helps with service and engine failures but does not replace policy and connection data in Log Viewer. A quiet file likewise does not prove that scanning is inactive. Sophos Firewall services and logs explains the log mapping.

Troubleshoot common errors methodically

  • Web Policy active but no malware inspection: Scan HTTP and decrypted HTTPS is missing from the firewall rule that actually matches.
  • HTTP test works, HTTPS test does not: The SSL/TLS inspection rule does not match, does not use Decrypt, or Web Proxy does not decrypt HTTPS.
  • Browser uses another path: QUIC is allowed or another firewall rule matches first.
  • File is not scanned despite the correct rule: A Web Exception bypasses Malware and content scanning, or the file exceeds the configured size limit.
  • EICAR is blocked, but not by the firewall: Endpoint protection, a file type rule, or a web category acted first. Check the firewall Rule ID and Malware log.
  • Legitimate archives are blocked: Check Action on malware scan failure, encryption, corruption, and nesting. Do not immediately change the global setting to Allow.
  • Dual Engine slows downloads: Compare appliance load, file sizes, concurrency, and Proxy or DPI mode with Single Engine in a controlled pilot.
  • Zero-Day Protection shows nothing: Check classic malware scanning, HTTPS decryption, file type, exceptions, and Use Zero-day protection separately.
  • A scanning option is missing or cannot be saved: Check the status and expiry of Web Protection, Email Protection, or Zero-Day Protection under Administration > Licensing, then synchronize the licenses. Do not work around this with a broader allow rule.
  • An FTP file is not scanned: Check the matching Rule ID, Scan FTP for malware, service, and Maximum file scan size for FTP together. The HTTP/HTTPS switch does not enable FTP scanning.
  • An email attachment is not detected: First identify the actual mail path: MTA, Legacy SMTP, or POP/IMAP. Then correlate the protocols and ports selected in the matching firewall rule, the applicable email policy, Single/Dual Antivirus, exceptions, and Mail or Malware logs.

Log Viewer, Policy Tester, and Packet Capture show which firewall rule and policy actually apply.

Roll back changes while preserving state

A rollback restores only the values changed during the pilot. Restore the recorded settings in reverse order: the SSL/TLS inspection rule and its position, the firewall rule with its Rule ID and position, the Proxy/DPI choice, scanning and QUIC switches, the global Single/Dual Engine selection, and the values from show scanengine. Do not delete a firewall rule or disable malware scanning globally because one download fails.

Save the configuration and repeat two checks: a normal representative download must work, and the isolated EICAR test must show exactly the expected pre-change behaviour. If the Rule ID, decryption status, or log action differs from the baseline, the rollback is not complete. The full backup is the emergency path for a wider misconfiguration, not the first response to one checkbox.

Special case when upgrading to SFOS 22.0 GA

A narrowly scoped upgrade issue for SFOS 22.0 GA Respin Build 411 is documented under NC-177529. During this upgrade, messages such as Malware Unscannable may appear temporarily, often for www.msftconnecttest.com. At that moment, the new Sophos scan engine is not yet available when it is the only engine selected in Single Engine mode. Legacy Web Proxy then displays block pages, while page loads can fail with the DPI Engine; the interruption may last approximately one minute longer. Before every upgrade, also verify the current maintenance release and supported upgrade paths; the linked upgrade check covers this version-dependent verification.

Administrators upgrading specifically to this GA version switch from Single engine to Dual engine under Web > General settings before the upgrade and return to the previously used Single engine after the upgrade has completed. This temporary measure is not a general recommendation for MR1, MR2, or later releases. SFOS 22 upgrade check describes the complete upgrade path and other blockers.

FAQ

Is a Web Policy sufficient for malware scanning?

No. A Web Policy controls web categories and other policy decisions. For antivirus scanning, Scan HTTP and decrypted HTTPS must additionally be enabled in the firewall rule that actually matches.

Should you use single or dual engine?

Single Engine with Sophos as Primary Engine offers better performance and supports Zero-Day Protection. Dual Engine increases detection coverage but requires more resources. The appropriate choice depends on the protection requirements, the appliance, and measured load.

Why is an HTTPS test file not detected?

Often, the connection is not decrypted, an Exception bypasses the scan, QUIC or another firewall rule changes the path, or the download exceeds the scan limit. The SSL/TLS inspection log, Rule ID, and Malware log must be checked together.

Should unscannable content be allowed?

Block is the safer starting point for normal client networks. If a legitimate process is disrupted, investigate and handle the specific file path as narrowly as possible instead of allowing uninspected content globally.

Does firewall malware scanning replace endpoint protection?

No. The firewall only sees traffic that passes through its scan path and cannot fully inspect encrypted or excluded content. Endpoint protection, EDR, or MDR remain necessary for files, processes, and behaviour on the device.