Skip to content
Avanet

Detect and Control Generative AI with Sophos Firewall

Sophos Firewall can identify known GenAI applications using application signatures and allow or block them through the Generative AI category. For a safe rollout, usage should first be allowed and logged for a small pilot group. The detection results can then be checked before blocking is enabled.

The firewall does not assess prompts and cannot guarantee that it will detect every new AI service. It controls the network traffic of recognised applications. Synchronized Application Control can supplement this visibility with information from Sophos Endpoints, but it does not enforce a separate policy itself.

Quick Procedure

  1. Define a small pilot group or separate test network.
  2. Under Applications > Application filter, create a dedicated policy from the Allow All template.
  3. Select the policy under Identify and control applications (App control) in the firewall rule that actually matches, and enable Log firewall traffic.
  4. Generate test traffic using approved and unapproved GenAI services.
  5. In Log Viewer, check which Rule ID, application, category, action and user or client are logged.
  6. To introduce blocking, create a second Application Filter, select the Generative AI category with Select All, and set the action to Deny.
  7. Enable the blocking policy in the pilot rule only, then test again.

The test is successful when a known service is assigned to the expected application or category, the traffic matches the intended pilot rule, and users outside the pilot group remain unaffected.

What Sophos Firewall Detects for GenAI

Application Control and Synchronized Application Control complement each other, but perform different tasks.

Application Control Is the Foundation

Standard Application Control inspects traffic passing through the firewall and assigns known applications based on Sophos signatures. It does not require Sophos Endpoint. The policy is defined through an Application Filter and enabled in a firewall rule.

The Generative AI category has been available in earlier supported SFOS versions and is maintained through application signature updates. SFOS 22.0 MR2 did not introduce the category, but improves the additional detection provided through Sophos Endpoint.

Application Control requires a valid Web Protection subscription. Pattern updates must be current because Sophos delivers new or changed applications through these signatures. The services included in a broad category rule can therefore change during operation.

The general principles behind Application Filters, firewall rule assignment, signatures and false positives are covered in Setting Up and Testing Sophos Firewall Application Control.

Synchronized Application Control Adds Endpoint Telemetry

Synchronized Application Control receives additional information through Security Heartbeat about applications running on Sophos Endpoints. Unknown applications initially appear under SyncAppCtl discovered. The New, Mapped and Customized labels show whether an application has been newly detected, mapped automatically or adjusted manually.

Enforcement still takes place through an Application Filter in a firewall rule. Synchronized Application Control therefore improves detection and categorisation, but does not block traffic on its own.

This additional visibility requires:

  • a valid Web Protection subscription for Application Control;
  • Network Protection for Security Heartbeat;
  • a Sophos Central account;
  • an endpoint managed through Sophos Central with a trial or full licence;
  • a functioning Security Heartbeat connection.

In environments using Microsoft Defender or another endpoint product, this additional Sophos telemetry is not available. The standard Application Control method remains available.

Set Up a GenAI Pilot

The following names are used in this example:

  • pilot group: GG-SFOS-GenAI-Pilot
  • allowing Application Filter: APP-GenAI-Pilot
  • blocking Application Filter: APP-GenAI-Block
  • firewall rule: LAN-Pilot-to-WAN

These names can be changed freely. The user group must come from the organisation’s authentication source, and the firewall rule must match the local zones, networks, services and security policies. Without reliable user identification, a separate test network is usually simpler than a user-based pilot rule.

Scope the Pilot Rule Correctly

The pilot rule should use the same required NAT, web, IPS and TLS settings as the existing client internet path. Place it directly above the more general internet rule, not indiscriminately at the top of the entire rule set.

For a user-based rule, enable Match known users and select GG-SFOS-GenAI-Pilot. For a test network, use its specific network object under Source networks and devices. Then confirm that no earlier rule already processes the same traffic.

Understanding and Configuring Sophos Firewall Rules Safely explains how source, destination, users and rule order interact.

Allow and Log GenAI First

Sophos Firewall does not provide a dedicated Monitor action in an Application Filter. Monitoring therefore means allowing the traffic, enabling firewall logging and reviewing the matches.

Under Applications > Application filter:

  1. Open Add.
  2. Enter APP-GenAI-Pilot as the Name.
  3. Select Allow All as the Template.
  4. Select Save.

Then open the LAN-Pilot-to-WAN rule under Rules and policies > Firewall rules:

  1. Leave Action set to Accept.
  2. Enable Log firewall traffic.
  3. Under Other security features, select APP-GenAI-Pilot for Identify and control applications (App control).
  4. Save the rule and check its position.

Applications are now identified and logged, but are not yet blocked based on the GenAI category. The pilot phase should cover at least one representative work cycle involving the affected user groups and approved business services. A fixed number of days is less useful than a test that reflects actual working practices.

Block GenAI for the Pilot Group

After reviewing the results, create a separate blocking policy. This preserves the original allowing state and makes it available for rollback.

Under Applications > Application filter:

  1. Open Add.
  2. Enter APP-GenAI-Block as the Name.
  3. Select Allow All as the Template and save it.
  4. Open the new policy again and select Add.
  5. Use Select All and set the filter to Category: Generative AI.
  6. Set Action to Deny and Schedule to All the Time.
  7. Save the filter rule, then save the policy.

In LAN-Pilot-to-WAN, replace the existing APP-GenAI-Pilot filter with APP-GenAI-Block. The firewall rule itself remains set to Accept; the assigned Application Filter enforces the GenAI block.

If specific GenAI services are approved for business use, do not immediately block the entire category for every user. Clearly separated user groups or networks and a specific rule for approved use are safer. Alternatively, start by blocking individual unapproved applications rather than the entire category. This keeps it clear who is permitted to use each service and for what purpose.

Verify the Effect and Tighten the Policy

A successful page load or a visible block page does not prove that the intended policy was applied. Acceptance should check three levels:

  1. Rule match: Log Viewer shows the Rule ID for LAN-Pilot-to-WAN.
  2. Detection: The application and category match the GenAI service being tested.
  3. User impact: The pilot group receives the expected action, while an unaffected user or another test network remains unchanged.

Allowed usage can be reviewed under Applications > Cloud applications and Reports > Applications & web > User app risks & usage. Cloud Applications only shows allowed applications with traffic. For blocked tests, use Log Viewer and Reports > Applications & web > Blocked user apps. With Synchronized Application Control, the Synchronized applications report provides additional information.

If the expected events are missing from Log Viewer, check under System services > Log settings whether the required types are enabled for Local Reporting, Central Reporting or Syslog. Central Firewall Reporting is suitable for longer-term analysis.

When Detection Is Incorrect

  • Different Rule ID: An earlier firewall rule is processing the traffic. Check the match criteria and rule order.
  • No application or only generic detection: Check application patterns, HTTPS visibility, QUIC and the client actually being used.
  • Local application missing from Synchronized Application Control: Check registration in Sophos Central, the endpoint licence and Security Heartbeat.
  • Blocking affects legitimate services: Immediately switch back to APP-GenAI-Pilot and narrow the policy to specific users, networks or applications.
  • IPv4 works but IPv6 does not: Check both rule sets and the client path actually in use separately.

For HTTPS, TLS Inspection can provide additional visibility, particularly for URL-based Micro Apps and more detailed cloud application information. However, it does not guarantee complete GenAI detection and should not be rolled out indiscriminately to every user solely for this test. QUIC or HTTP/3 can also affect the expected web control.

The detailed procedure for Rule ID, Log Viewer and Packet Capture is covered in Testing a Sophos Firewall Rule.

Rollback

For rollback, select APP-GenAI-Pilot again in the pilot rule or disable the pilot rule. Before disabling it, confirm that the general rule below will process the traffic as intended.

Do not delete the blocking policy initially. This keeps the configuration, change documentation and related logs traceable while the cause of unexpected blocking is investigated.

Limitations and Ongoing Operation

Application Control manages recognised network connections. It does not read prompts, assess the business data entered, or replace DLP or comprehensive SaaS or GenAI governance. Blocking a category also does not automatically prevent every access attempt through new domains, unknown applications, private devices or other network paths.

The technical policy therefore requires an organisational decision:

  • Which GenAI services are approved?
  • Which users or teams may use them?
  • What data may be processed there?
  • Who approves an exception?
  • When will signatures, matches and exceptions be reviewed again?

After pattern or firmware updates, review the category rule matches again. A good operational state is not the broadest possible block, but a set of comprehensible rules, stable detection, documented exceptions and a clear owner.