Understand and operate Sophos Firewall Zero-Day Protection
Sophos Firewall Zero-Day Protection analyses suspicious downloads and email attachments via SophosLabs Intelix. The firewall sends appropriate, risky files to the cloud service, where machine learning, reputation, sandbox analysis and threat research work together. The goal is not only to block known malware, but also to better classify new or unusual files.
It is important for admins: Zero-Day Protection is not a replacement for clean rules, web protection, mail protection, TLS Inspection, logging or endpoint protection. The function is an additional protection and analysis module. It is particularly helpful when files enter the network via web downloads or email attachments and classic signatures do not yet provide a clear decision.
Which protection article fits?
Zero-Day Protection primarily answers the question of how suspicious files are analyzed. Depending on the problem, the better way to start is with web access, mail flow, network attacks, encrypted traffic or evaluation:
- Check suspicious downloads or email attachments with Intelix: This article.
- Configure and test classic web malware scanning with single or dual engine: Configure and test Sophos Firewall malware scanning.
- Schedule Web Categories, URL Groups, SafeSearch or Download Rules: Sophos Firewall Set up web protection with web policies.
- Make HTTPS traffic visible and plan exceptions cleanly: Insert Sophos Firewall TLS Inspection correctly.
- Distribute CA certificate for HTTPS scanning to clients: Sophos Firewall Install CA certificate for HTTPS scanning.
- Check email traffic in MTA mode and operate mail protection: Sophos Firewall Set up mail protection in MTA mode.
- Block exploits and attack patterns in network traffic: Sophos Firewall Set up IPS and test it safely.
- Handle malicious IPs, domains or URLs via IoC lists: Sophos Firewall Set up threat feeds and operate them securely.
- Classify NDR, Active Threat Response, XDR, MDR or SIEM evaluation: Sophos Firewall NDR and Active Threat Response operate.
- Track unexpected drops or blocks: Sophos Firewall Analyze dropped packets.
This separation prevents false expectations: Zero-Day Protection evaluates files, but it does not replace a web policy, IPS, mail relay planning or central log evaluation. The best protection is achieved when the file, web, mail, network and logging layers work together.
Where Zero-Day Protection helps in practice
Zero-Day Protection is particularly relevant in these scenarios:
- Users download executable files, archives or documents from the Internet.
- Email attachments should be checked more closely before delivery or release.
- A file is not yet clearly known, but seems suspicious.
- A download should not only be scanned locally, but also monitored in a sandbox.
- A security incident must be better assessed using a detailed report.
The feature fits well with a tiered security model: Firewall rules limits allowed traffic, TLS Inspection makes encrypted web traffic more auditable, Web Protection and Mail Protection assess content, and Zero-Day Protection complements these controls with cloud analytics and sandbox reports.
Requirements and limits in SFOS 22
Zero-Day Protection requires its own subscription. It is included in the Xstream Protection bundle and covers machine learning, sandboxing file analysis and threat intelligence. Under Administration > Licensing, the status must be Subscribed or Evaluating; a 30-day evaluation is available. A Base License or Web Protection alone does not include it. Zero-Day Protection isn’t supported in an air-gap deployment because the cloud connection is unavailable. An internet-connected firewall automatically synchronizes licenses every 24 hours. If a newly changed Zero-Day subscription still appears stale, allow for that cycle or trigger license synchronization before troubleshooting the policy path.
The protection modules and policies for the actual data path must also be active. A plain allow rule without matching security profiles does not provide the same protection. For web downloads, Single engine requires Sophos as the primary antivirus engine; the alternative is Dual engine. The same requirement applies in an SMTP route and scan policy when Single antivirus is selected. Check these settings under Web > General settings and in the matching SMTP policy under Email > Policies and exceptions.
Important limits in operation:
- The firewall does not send every file type to Intelix, but primarily risky file types.
- Many non-hazardous file types, for example typical image formats, are not sent for detonation.
- Exceptions can exclude files from the analysis and thus reduce the protective effect.
- Cloud analytics requires connectivity to Sophos services and may delay downloads.
- The firewall requires outbound TCP 443 to
*.sandbox.sophos.com; TLS interception or an upstream proxy must not break this service connection. - Releasing a file before analysis is complete may expose malicious content.
- Zero-Day Protection does not replace endpoint detection and response, MDR or a sound incident response process.
If the firewall sees little because HTTPS is not decrypted or rules are running without security profiles, Zero-Day Protection also remains restricted. The article Sophos Firewall Logs: Which function writes to which log? helps with log and module assignment.
Activate in firewall rules
For web downloads, it is not enough for Zero-Day Protection to be licensed in general. The appropriate firewall rule must really match the web traffic and activate the required web scanning options.
The typical path is:
Rules and policies > Firewall rules
In the affected client internet rule, check:
- Source zone, Source network, Destination zone and Services match the test traffic.
- Log firewall traffic is active.
- A suitable Web Policy is selected in Web filtering.
- Scan HTTP and decrypted HTTPS is active.
- Use zero-day protection is active.
- For HTTPS downloads, TLS Inspection is planned and effective for the test traffic.
- QUIC/HTTP/3 does not bypass the expected HTTPS inspection path.
- Web Exceptions do not unintentionally skip malware scanning, policy checks or Zero-Day Protection analysis.
This does not guarantee that every download appears in the Zero-Day Protection view. Known files, non-critical file types or downloads outside the inspected path can be evaluated differently earlier. For acceptance, therefore check not only whether the checkbox is active, but whether a concrete download can be traced in Log Viewer, Web log, SSL/TLS inspection log and Downloads and attachments.
Important: Scan HTTP and decrypted HTTPS scans HTTP and already decrypted HTTPS traffic. The option does not automatically activate HTTPS decryption. In DPI setups, this needs matching Rules and policies > SSL/TLS inspection rules; in the web proxy path, Decrypt HTTPS during web proxy filtering is relevant. Without this visibility, Zero-Day Protection may see less of encrypted downloads even though the firewall rule formally looks correct.
Where Zero-Day Protection takes effect
Zero-Day Protection should not be viewed in isolation. The function only becomes relevant if a file actually runs through a suitable protection path.
Typical paths:
- Web download: The appropriate firewall rule, web protection, Scan HTTP and decrypted HTTPS, Use zero-day protection and, for HTTPS, often TLS Inspection must be in place beforehand. You can check the web log, SSL/TLS inspection log and the downloads-and-attachments view.
- Email attachment: The mail flow must pass through mail protection, appropriate attachment policy and malware check. You can control mail logs, quarantine and the downloads and attachments view.
- FTP download: Scan FTP for malware enables antivirus scanning, not Zero-Day cloud analysis. In SFOS 22, Use zero-day protection explicitly applies to HTTP and HTTPS downloads.
- Release or error status: The report is not yet completed or the analysis failed. Then the release process, user context, hash and other logs count.
- No visibility: Traffic does not pass through the protection path or the file type is not relevant. Then first check the firewall rule, policy, TLS, mailflow and file type.
For web downloads, the first thing that is important is whether the correct Web Policy is active in the firewall rule. For email attachments, the mail flow must actually run via Mail protection in MTA mode or a comparable checked path. If only a normal allow rule allows traffic, you should not expect a complete file analysis from Zero-Day Protection.
Be especially careful with Web Exceptions. In DPI and proxy mode, an exception can cause decryption, malware and content scanning, Zero-Day Protection or policy checks to be skipped for matching traffic. Exceptions should therefore be narrower than the actual protection rule and checked against Log Viewer, SSL/TLS inspection log and a real download.
Enable it for email attachments
In MTA mode, go to Email > Policies and exceptions > SMTP route and scan. Edit the policy that actually matches the sender, recipient and protected domain, then open Malware protection:
- Turn on Malware protection.
- Under Scanning, select Single antivirus with Sophos as the primary engine, or Dual antivirus. XGS 87/87w and 88/88w only support the primary engine.
- Turn on Use zero-day protection.
- Set the maximum file size in the associated field. This is an administrator-selected policy limit, not a universal product value: larger attachments aren’t analyzed.
- Save the policy and verify its order so that a broader policy doesn’t match first.
Choose the size limit from your real mail profile, bandwidth and acceptable wait time. A sensible starting point is the organization’s existing permitted attachment limit rather than a copied number. Validate an authorized test attachment by time, sender and recipient in Email > Mail logs, Email > Mail spool, and Monitor & analyze > Zero-day protection > Downloads and attachments. A spool item with status Zero-day protection is waiting for analysis. SFOS retries delivery for three days and discards the email after another four days; discarded messages remain visible in mail logs.
Analysis flow
1. Detection on the firewall
A file gets through the firewall via a download or as an email attachment. If the policy, file type and context match, the file is flagged for Zero-Day Protection. Known, clearly classified files can be evaluated beforehand by other protection modules.
2. Handover to SophosLabs Intelix
Eligible files are sent to a SophosLabs Intelix service over an encrypted connection. There the file is not only checked against known patterns, but is also evaluated using several levels of analysis.
3. Machine learning and reputation
SophosLabs Intelix evaluates characteristics, structure, global reputation and similarity to known good or malicious files. This is particularly helpful for new files that have not yet been widely seen.
4. Sandbox analysis
Sandbox analysis examines the file in an isolated environment. The evaluation combines dynamic and static analysis, deep learning, exploit detection, CryptoGuard and monitoring of file, storage, registry and network activities. For admins, the marketing term is less important than the question: What was the file actually trying to do?
5. Decision and report
At the end there is a rating, for example clean, likely clean, suspicious, malicious or PUA. Depending on the result, the file is released, blocked, or remains visible with an error or analysis state. The report helps to clearly justify a release, a block or further incident response steps.
Read reports correctly
The overview can be found in Sophos Firewall under Monitor & analyze > Zero-day protection > Downloads and attachments. There you can see activity data on suspicious downloads and email attachments, the analysis status, report details and release options.
In the list, do not only search by file name. Filters by time period, user, source, status and component are useful. Technically, Zero-Day Protection events appear in reports and syslog as their own log type. Depending on the path, the component is Web or Mail, and subtypes can include Allowed, Denied or Pending. This makes correlation with SIEM or Central Reporting cleaner.
The Detection Status gives a short view of analysis progress. For the full assessment, open View report or Show report instead of reading only the list entry. Especially with Pending, error status or a later release, the detailed report is the basis for the decision.
A report can contain, among others, these areas:
- Download details: Source, timing and affected user.
- Analysis summary: Overall evaluation of the file.
- Machine learning analysis: Features, structure and ML evaluation.
- Reputation analysis: Assessment based on global distribution.
- Detonation results: Behavior of the file during sandbox execution.
- Full file analysis: Signatures, certificates, resources, imports and exports.
- VirusTotal report: additional external detection situation.
When it comes to a suspicious file, you shouldn’t just look at the final status. Source, user, file name, target URL, process behavior, network activity and whether other systems have seen the same download are also relevant. If this results in an incident, the report should be merged with endpoint, mail, web and firewall logs.
Process for suspicious reports
A zero-day protection hit should be treated like a small security case, not like a pure web filter block.
Practical process:
- Open report and record status, file name, source, user, time and rating.
- Check whether it was a web download, an email attachment or another path.
- Compare web, mail and firewall logs for the same time period.
- If present, check endpoint or EDR events for the affected client.
- Document file hash, sender, URL or domain.
- Decide whether it is a false positive, a blocked attack, an unresolved suspicion or an incident.
- Only consider release if there is an understandable business reason.
- Document the decision and, if necessary, derive a URL group, mail policy, threat feed or endpoint measure.
When multiple users see the same file or domain, a single decision is often not enough. You should then check whether a web policy adjustment, a mail policy rule, a threat feed entry or an incident response is necessary.
Release files
Sophos Firewall allows release only for files or email messages that are still being analysed or have returned with an error status. Such a release may be necessary if a business process is blocked. However, it is unsuitable as a normal workaround.
Before releasing, you should at least check:
- Is the source trustworthy and expected?
- Was the user or department consulted about the context?
- Is there a hash, file name or sender that can be additionally checked?
- Are there endpoint or mail logs for the same process?
- Can the file be examined in an isolated environment or via a separate analysis tool?
- Is it documented who decided to release it and for what reason?
⚠️ Releasing a file before analysis is complete may result in malicious content being downloaded or delivered. In production environments, this decision should be documented and not delegated to routine first-level support.
After a release, analysis continues. This is important for operations: a released file can later still be classified as suspicious or malicious. Therefore, releases should be checked afterwards and, if the later rating is bad, endpoint, mail, web and firewall logs should be correlated again.
For individual files, the Avanet blog post SophosLabs Intelix - The cyber threat detection tool can help. However, this does not replace the evaluation in the specific network and user context.
Data centre and data protection
You can specify the data centre for the analysis under Monitor & analyze > Zero-day protection > Protection settings. By default, Sophos Firewall chooses the nearest data centre. Alternatively, you can deliberately select a data centre. Files are transferred to the Sophos cloud over a secure SSL connection.
This setting matters for privacy, data residency and internal requirements. Changing the data centre may lose analysis for files currently being processed. Record open items first, use a quiet maintenance window, then verify connectivity and new analyses. Region selection alone doesn’t settle retention, processing agreements or which file contents may be uploaded; assess those separately.
Use exceptions carefully
In the Protection settings, you can exclude file types from Zero-Day Protection analysis. File type detection is based on file extension and MIME header. Archives containing excluded file types can also be excluded.
Exceptions are technically practical, but safety-relevant. Each exception should have a clear justification:
- Which application or process creates the files?
- Why is the analysis disturbing or not useful?
- Is there a narrower exception than an entire file type?
- Is the exception checked regularly?
- Is it known what protective effect is lost as a result?
Broad exceptions for archives, scripts, Office files or executable files should be avoided. When Zero-Day Protection disrupts a legitimate process, the first step is often to check the policy, source path, affected user base or alternative deployment.
For a web exception, go to Web > Exceptions > Add an exception. Criteria of different types are combined with AND; multiple values within one criterion type are combined with OR. For HTTPS, URL-path patterns only match when traffic is decrypted, so use hostname matching if decryption isn’t available. Skipping Malware and content scanning automatically skips Zero-Day Protection. Skipping only Zero-day protection also removes analysis reports for matching files, even when malware scanning detects something. This is a persistent state change: narrow the exception to a hostname or URL pattern, select Save, turn on its switch, and record an owner and expiry date. To roll back, turn off or remove the exception and validate the same data path again.
Roll back a change safely
Restore the previous data path rather than switching off every protection layer:
- Record the previous rule, policy, engine, size limit, data centre and exception values before changing them.
- For web problems, first disable the new narrow exception or restore rule order. Only revert Scan HTTP and decrypted HTTPS or TLS Inspection if that specific change caused the fault and the reduced protection is accepted.
- For mail problems, restore the edited SMTP Route and Scan policy. Don’t blindly release waiting messages: Release now makes an unchecked file available immediately, although analysis continues.
- After rollback, verify the rule match, web or mail log, and an authorized download or test attachment. If
*.sandbox.sophos.com:443remains unreachable or new objects stayPending, the rollback isn’t successful.
Check releases and exceptions regularly
Zero-Day Protection is not just a feature that is switched on once. Its operational value comes from reviewing reports, releases and exceptions regularly. Otherwise, risky decisions remain active long after the original business reason has disappeared.
These points are particularly helpful for the review:
- Released file: Check the reason for the release, affected user or department, hash, file source, expiry date and later evaluation.
- File type exception: Check affected application, owner, review date, closer alternative and risk for archives, scripts or Office files.
- Recurring error status: Check Sophos connectivity, file size, file type, policy, data center and possible support case.
- Many hits from one source: Check web or mail policy, URL, sender, user group, threat feed, URL group or blocklist.
An exception is not a normal firewall rule cleanup. Such entries should have an owner, a reason and a review date. For recurring releases, you should also compare endpoint, mail, web and firewall logs so that a single exception does not turn into a permanent bypass unnoticed.
Troubleshooting
No entries visible
If no entries appear under Downloads and attachments, you should first check whether the traffic actually goes through the appropriate firewall rule and security profile. For web downloads, Scan HTTP and decrypted HTTPS and Use zero-day protection in the firewall rule are particularly relevant. For HTTPS traffic, missing TLS Inspection can explain why the firewall sees less content. Then check web, mail, malware and zero-day settings.
Also check whether a Web Exception excludes the relevant traffic from decryption, malware and content scanning or Zero-Day Protection. If an exception applies, the Zero-Day Protection configuration can look correct and still produce no entry.
For tests, do not create false expectations with files that are already known locally or globally. If reputation or other protection modules already clearly rate a file, a complete new sandbox analysis does not necessarily have to be visible. For acceptance tests, time window, test client, Rule ID, URL, file name and hash are more important than a single browser download without log correlation.
Downloads take too long
A sandbox analysis can take time. If users regularly wait for long periods of time, you should check whether many large or frequently changing files are being analyzed, whether the processes affected are legitimate and whether a narrow technical exception is justifiable. A blanket deactivation is usually the wrong first step.
Lots of false positives
For recurring false positives, check the report details, file source, hashes, reputation, affected users and application. Only when the pattern is understood should you set exceptions. For dynamic block lists and IOC operations, Sophos Firewall Set up threat feeds and operate them securely is a related topic.
Release has been requested
A release should be treated as a security decision. If the department only reports “urgent”, that is not enough. You need source, purpose, file, user, risk assessment and a documented decision.
Analysis remains Pending or ends in Error
First check System services > Log settings. The Zero-day protection log type must be selected under Local reporting, the intended syslog server, or Central reporting. Then verify DNS, routing and outbound TCP 443 to *.sandbox.sophos.com. For mail, Email > Mail spool shows waiting messages separately. If different eligible file types fail repeatedly, capture timestamps, hash, component, policy or Rule ID and report status for Sophos Support.
Check SFOS 22 release notes and known issues
Use the Sophos Firewall firmware update guide for the current release-notes and known-issues verification workflow. Its snapshot from September 8, 2026 records 22.0 MR2 Build 546 as current. SFOS 22 introduces a new Sophos anti-malware engine with global reputation lookups and AI/ML detections. This engine change doesn’t replace the separate Zero-Day subscription or policy switches.
Before an upgrade or broad rollout, follow that guide to search the release notes and Known Issues List for Sophos Firewall, Zero-day, sandbox, email, and the target release rather than relying on an earlier search result. MR2’s resolved issues include a mail-spool fault, so mail deployments should review the Email fixes as well as the Zero-Day pages.
Operational checklist
- Zero-Day Protection licence and module status checked.
- Web and mail policies with malware and security scanning checked.
- In web firewall rules, Scan HTTP and decrypted HTTPS and Use zero-day protection checked.
- TLS Inspection or web proxy decryption planned where encrypted web downloads should be inspected sensibly.
- Web Exceptions checked for unintended Zero-Day bypasses.
- Data centre deliberately chosen for analysis or documented as standard.
- No broad file type exceptions without owner and review date.
- Downloads and attachments view checked regularly.
- Release process defined for analysed or errored files.
- Reports correlated with endpoint, mail, web and firewall logs.
- Syslog, Central Reporting or SIEM taken into account for longer traceability.