Skip to content
Avanet

Detect and Control Generative AI with Sophos Firewall

Sophos Firewall can identify known GenAI applications using application signatures and allow or block them through the Generative AI category. For a safe rollout, usage should first be allowed and logged for a small pilot group. The detection results can then be checked before blocking is enabled.

The firewall does not assess prompts and cannot guarantee that it will detect every new AI service. It controls the network traffic of recognised applications. Synchronized Application Control can supplement this visibility with information from Sophos Endpoints, but it does not enforce a separate policy itself.

Quick Procedure

  1. Define a small pilot group or separate test network.
  2. Under Applications > Application filter, create a dedicated policy from the Allow All template.
  3. Select the policy under Identify and control applications (App control) in the firewall rule that actually matches, and enable Log firewall traffic.
  4. Generate test traffic using approved and unapproved GenAI services.
  5. In Log Viewer, check which Rule ID, application, category, action and user or client are logged.
  6. To introduce blocking, create a second Application Filter, select the Generative AI category with Select All, and set the action to Deny.
  7. Enable the blocking policy in the pilot rule only, then test again.

The test is successful when a known service is assigned to the expected application or category, the traffic matches the intended pilot rule, and users outside the pilot group remain unaffected.

What Sophos Firewall Detects for GenAI

Application Control and Synchronized Application Control complement each other, but perform different tasks.

Application Control Is the Foundation

Standard Application Control inspects traffic passing through the firewall and assigns known applications based on Sophos signatures. It does not require Sophos Endpoint. The policy is defined through an Application Filter and enabled in a firewall rule.

The Generative AI application category is visible under Applications > Application list. Before starting the pilot, check whether Sophos lists the services you intend to test. A catalogue entry does not prove detection on your own network; that is the purpose of the later client test.

Application Control requires a valid Web Protection subscription. Check the status under Backup & firmware > Pattern updates and use Update pattern now if required. When the application signature database is updated, new applications are automatically added to matching category-based filters and rules. The services covered by a broad category rule can therefore change during operation.

SFOS 22.0 MR2 did not introduce the category. Sophos Endpoint categorises Generative AI applications more accurately in this version and shares the information through Synchronized Application Control. This improves visibility, reporting and the basis for policy control, but does not guarantee detection of a specific service.

The general principles behind Application Filters, firewall rule assignment, signatures and false positives are covered in Setting Up and Testing Sophos Firewall Application Control.

Synchronized Application Control Adds Endpoint Telemetry

Synchronized Application Control receives additional information through Security Heartbeat about applications running on Sophos Endpoints. Unknown applications initially appear under SyncAppCtl discovered. The New, Mapped and Customized labels show whether an application has been newly detected, mapped automatically or adjusted manually.

Enforcement still takes place through an Application Filter in a firewall rule. Synchronized Application Control therefore improves detection and categorisation, but does not block traffic on its own.

This additional visibility requires:

  • a valid Web Protection subscription for Application Control;
  • Network Protection for Security Heartbeat;
  • a Sophos Fusion (formerly Sophos Central) account;
  • an endpoint managed through Sophos Fusion with a trial or full licence;
  • a functioning Security Heartbeat connection.

In environments using Microsoft Defender or another endpoint product, this additional Sophos telemetry is not available. The standard Application Control method remains available.

Set Up a GenAI Pilot

The following names are used in this example:

  • pilot group: GG-SFOS-GenAI-Pilot
  • allowing Application Filter: APP-GenAI-Pilot
  • blocking Application Filter: APP-GenAI-Block
  • firewall rule: LAN-Pilot-to-WAN

These names can be changed freely. The user group must come from the organisation’s authentication source, and the firewall rule must match the local zones, networks, services and security policies. Without reliable user identification, a separate test network is usually simpler than a user-based pilot rule.

Scope the Pilot Rule Correctly

The pilot rule should use the same required NAT, web, IPS and TLS settings as the existing client internet path. Place it directly above the more general internet rule, not indiscriminately at the top of the entire rule set.

For a user-based rule, enable Match known users and select GG-SFOS-GenAI-Pilot. For a test network, use its specific network object under Source networks and devices. Then confirm that no earlier rule already processes the same traffic.

Understanding and Configuring Sophos Firewall Rules Safely explains how source, destination, users and rule order interact.

Allow and Log GenAI First

Sophos Firewall does not provide a dedicated Monitor action in an Application Filter. Monitoring therefore means allowing the traffic, enabling firewall logging and reviewing the matches.

Under Applications > Application filter:

  1. Open Add.
  2. Enter APP-GenAI-Pilot as the Name.
  3. Select Allow All as the Template.
  4. Select Save.

Then open the LAN-Pilot-to-WAN rule under Rules and policies > Firewall rules:

  1. Leave Action set to Accept.
  2. Enable Log firewall traffic.
  3. Under Other security features, select APP-GenAI-Pilot for Identify and control applications (App control).
  4. Save the rule and check its position.

Applications are now identified and logged, but are not yet blocked based on the GenAI category. The pilot phase should cover at least one representative work cycle involving the affected user groups and approved business services. A fixed number of days is less useful than a test that reflects actual working practices.

Block GenAI for the Pilot Group

After reviewing the results, create a separate blocking policy. This preserves the original allowing state and makes it available for rollback.

Under Applications > Application filter:

  1. Open Add.
  2. Enter APP-GenAI-Block as the Name.
  3. Select Allow All as the Template and save it.
  4. Open the new policy again and select Add.
  5. Use Select All and set the filter to Category: Generative AI.
  6. Set Action to Deny and Schedule to All the Time.
  7. Save the filter rule, then save the policy.

In LAN-Pilot-to-WAN, replace the existing APP-GenAI-Pilot filter with APP-GenAI-Block. The firewall rule itself remains set to Accept; the assigned Application Filter enforces the GenAI block.

If specific GenAI services are approved for business use, do not immediately block the entire category for every user. Clearly separated user groups or networks and a specific rule for approved use are safer. Alternatively, start by blocking individual unapproved applications rather than the entire category. This keeps it clear who is permitted to use each service and for what purpose.

Do Not Confuse Application and Web Categories

Generative AI is an application category. Web > Categories, in contrast, manages URL categories that take effect through a Web policy in the firewall rule. A custom web category with the same name is not automatically synchronised with the application catalogue and is not an equivalent replacement for the Application Filter.

SFOS 23.0 version boundary: A built-in Generative AI web category is also documented here. It covers websites and services whose primary purpose is creating or transforming content using prompts; websites where generative AI is not the primary purpose are excluded. This URL classification takes effect through a Web Policy, not application signatures. It is neither a custom category nor an administrator-maintained domain list, and does not mean complete AI detection. This does not establish availability in SFOS 22.0. Web categories and policies explain the web path. Before blocking, check the category on the deployed version and confirm web and application decisions separately using real pilot requests and logs.

A custom URL category, or preferably a URL group, can provide an additional layer when the organisation maintains a list of approved or blocked domains. Sophos recommends URL groups for domain-only matching because they perform better and are less likely to cause false positives than custom categories. Domain entries include subdomains; keywords inspect the entire URL and can match unexpectedly through query parameters. Do not use keywords as an allow exception.

The supplementary path is Web > URL groups or Web > Categories, followed by Web > Policies, and finally Rules and policies > Firewall rules > Web filtering > Web policy. This domain list needs an owner and a review date because GenAI providers change hosts, CDNs and sign-in paths. This guide deliberately does not prescribe a static list.

Verify the Effect and Tighten the Policy

A successful page load or a visible block page does not prove that the intended policy was applied. Acceptance should check three levels:

  1. Rule match: Log Viewer shows the Rule ID for LAN-Pilot-to-WAN.
  2. Detection: The application and category match the GenAI service being tested.
  3. User impact: The pilot group receives the expected action, while an unaffected user or another test network remains unchanged.

Allowed usage can be reviewed under Applications > Cloud applications and Reports > Applications & web > User app risks & usage. Cloud Applications only shows allowed applications with traffic. New cloud applications initially have the classification new; sanctioned, unsanctioned and tolerated are administrative assessments. A classification applies only to new traffic and does not allow or block anything by itself. An Application Filter must use that criterion and be assigned to the matching firewall rule.

For blocked tests, use Log Viewer and Reports > Applications & web > Blocked user apps. A denied Application Filter match should appear under Content Filtering > Application > Denied; check the allowed control request under Firewall > Firewall Rule > Allowed. With Synchronized Application Control, the Synchronized applications report provides additional information. Firewall sessions may not be logged until the Connection Destroy event. If a newly generated entry is missing, end the test session cleanly and refresh the filter rather than immediately assuming that detection failed.

If the expected events are missing from Log Viewer, check at least the required Firewall and Content filtering types under System services > Log settings > Local reporting. Log firewall traffic must also be enabled in the pilot rule. Central Reporting and Syslog have separate columns; selecting them does not enable local display. Central Firewall Reporting is suitable for longer-term analysis.

When Detection Is Incorrect

  • Different Rule ID: An earlier firewall rule is processing the traffic. Check the match criteria and rule order.
  • No application or only generic detection: Check the entry under Applications > Application list, the status under Backup & firmware > Pattern updates, the HTTPS path, QUIC, Web Exceptions and the client actually being used. Packet Capture confirms the network path, not the application classification.
  • Local application missing from Synchronized Application Control: Check registration in Sophos Fusion, the endpoint licence and Security Heartbeat.
  • Blocking affects legitimate services: Immediately switch back to APP-GenAI-Pilot and narrow the policy to specific users, networks or applications.
  • IPv4 works but IPv6 does not: Check both rule sets and the client path actually in use separately.

For HTTPS, TLS Inspection can provide additional visibility, particularly for URL-based Micro Apps and more detailed cloud application information. DPI mode requires a matching rule under Rules and policies > SSL/TLS inspection rules with Action: Decrypt. In proxy mode, use Use web proxy instead of DPI engine and Decrypt HTTPS during web proxy filtering in the firewall rule. Scan HTTP and decrypted HTTPS scans already decrypted traffic; it does not enable decryption itself. The CA in use must be installed as trusted on the pilot clients.

If the design also relies on a Web Policy or URL category, enable Block QUIC protocol in the same pilot rule. SFOS then drops outbound UDP to ports 80 and 443; QUIC cannot be scanned by the web filter and bypasses its checks. This does not establish that every QUIC flow bypasses every other firewall function. The positive test only needs to show that the browser falls back to TCP and the intended web or TLS policy takes effect. TLS decryption and QUIC blocking still do not guarantee complete GenAI detection and should not be rolled out indiscriminately to all users solely for this test.

The detailed procedure for Rule ID, Log Viewer and Packet Capture is covered in Testing a Sophos Firewall Rule.

Roll Back Without Losing the Original State

Before switching, record the pilot rule’s previous Application Filter, Web Policy, Block QUIC protocol setting, web proxy or DPI mode, associated SSL/TLS rule, rule state and position, and NAT assignment. During rollback, restore only the fields that were changed and select APP-GenAI-Pilot as the Application Filter again.

Disable a separate pilot rule only after confirming that the general rule below will process the traffic as intended. Then start new sessions and repeat both the allowed control request and the previously blocked GenAI request. Both must once again show the documented original Rule ID and action.

Do not initially delete the blocking policy, URL Group or test objects. This keeps the configuration, change documentation and related logs traceable while the cause of unexpected blocking is investigated. Do not change shared TLS, web, NAT or authentication objects as part of this rollback.

Limitations and Ongoing Operation

Application Control manages recognised network connections. It does not read prompts, assess the business data entered, or replace DLP or comprehensive SaaS or GenAI governance. Blocking a category also does not automatically prevent every access attempt through new domains, unknown applications, private devices or other network paths.

The technical policy therefore requires an organisational decision:

  • Which GenAI services are approved?
  • Which users or teams may use them?
  • What data may be processed there?
  • Who approves an exception?
  • When will signatures, matches and exceptions be reviewed again?

After pattern or firmware updates, review the category rule matches again. Before changing firmware, also follow Perform a Sophos Firewall Firmware Update: it covers checking available builds and supported upgrade paths, validating the active version after restart, and troubleshooting failed updates and rollbacks. A good operational state is not the broadest possible block, but a set of comprehensible rules, stable detection, documented exceptions and a clear owner.