Set up Sophos Firewall surfing and network traffic quotas
A Surfing quota limits the usable internet time of an authenticated user. A Network traffic quota, by contrast, limits the amount of data transferred. Both policies are assigned to a user or group and are suitable, for example, for training rooms, guests, or clearly defined usage packages.
For temporary guests, account creation, validity, Captive Portal, and cleanup are planned separately. The full lifecycle is covered in Create and securely manage guest users on Sophos Firewall; this article focuses on quotas.
The short path for a controlled introduction is:
- Decide whether to limit time consumption, data volume, or both.
- Create a new pilot policy under Profiles > Surfing quota or Profiles > Network traffic quota.
- Assign the policy to a small pilot group under Authentication > Groups or to one test user under Authentication > Users.
- Reauthenticate the user and verify the recognized identity under Current activities > Live users.
- Use a user-based firewall rule with Log firewall traffic for the test.
- Open the user under Authentication > Users and review consumption with View usage.
- Test the limit, the next cycle, and rollback before adding more users.
⚠️ Reset user accounting resets both consumed surfing time and network traffic counters. This changes state and is not a general diagnostic button. Before a reset, document the user, current values, time, and reason. A shared production quota is likewise not edited directly; use a separate pilot policy for testing.
Choose the function that fits the requirement
Four similarly named functions solve different tasks:
- Access Time allows or blocks users during fixed time windows. It does not count consumption.
- Surfing quota gives a user a consumable time allowance for internet access.
- Network traffic quota gives a user a consumable data allowance.
- Traffic shaping limits or prioritizes bandwidth. A low data rate is not a data quota.
A Web Policy also offers a Quota action for time-limited access to specific web categories. This policy quota belongs to web proxy logic and is not the same feature as the user-based surfing quota in this article.
A quota creates neither a firewall rule nor a user identity. The firewall must recognize the user, the network path must be allowed, and the test traffic must match the expected rule. Only then can the quota be validated meaningfully.
Plan the example and prerequisites
The continuous example uses a small pilot group with two separate policies:
- Group:
Quota_Pilot - Test user:
quota-pilot - Surfing quota:
Students_InternetTime - Cycle type:
Cyclic (repeat access) - Cycle hours:
24 - Maximum access time:
02:00 - Network traffic quota:
Students_DataVolume - Restriction:
Total network traffic - Cycle type:
Cyclic - Cycle period:
Day - Quota per cycle:
5000 MB - Maximum quota:
Unlimited
These are deliberately small documentation examples: each 24-hour cycle provides two hours of internet time, and each day provides 5000 MB of data volume. Adapt names, time, data volume, cycle, and overall limit to the actual usage agreement. Small test limits must not be copied into a production-only policy without checking their impact.
Before configuration, verify the following:
- The pilot user can sign in with the intended authentication method.
- The username and source address appear under Current activities > Live users.
- For AD users, the Group field under Authentication > Users is correct.
- A suitable user-based firewall rule allows the test traffic and has Log firewall traffic enabled.
- Existing surfing quota, network traffic, access time, and traffic shaping assignments are documented.
- The previous state and an alternative test user are known.
If the user is not visible as a Live User, correct authentication first. A quota cannot reliably assign unknown traffic, or traffic handled only by IP, to a normal user allowance.
Create a surfing quota
A surfing quota counts consumed internet time. In the SFOS 22 help, the same object is documented under both Profiles > Surfing quota and Web > Surfing quotas. Use the entry shown in WebAdmin on the deployed build.
Choose Cyclic or Non-cyclic
- Cyclic (repeat access): The time allowance is provided again in recurring cycles. Unused time does not carry over to the next cycle.
- Non-cyclic (one-time access): The time allowance is provided once. The user is disconnected after it is consumed.
In addition, Validity period limits how many days the policy remains valid. Maximum access time defines the usable time. When the maximum is reached, the user is disconnected even if the quota validity period has not expired.
For the pilot example:
- Open Profiles > Surfing quota > Add. If the build shows the feature under Web > Surfing quotas, select Add there.
- Set Name to
Students_InternetTime. - Enter, for example,
Pilot: 2h per 24h, Owner ITas the Description. - Set Cycle type to Cyclic (repeat access).
- Set Cycle hours to
24. - Deliberately define the Validity period for the pilot, or select Unlimited only if no expiration boundary is required.
- Set Maximum access time to
02:00. - Save with Save.
The saved policy does not yet have an effect. Only assignment to a user or group connects the time allowance to an identity.
Create a network traffic quota
A network traffic quota counts transferred data volume. It does not limit speed. A user can therefore consume the allowance quickly or slowly; an appropriate traffic shaping policy is additionally planned when a bandwidth limit is required.
Limit total traffic or upload and download separately
- Total network traffic: One shared allowance counts upload and download together.
- Individual network traffic (Upload & download): Upload and download receive separate limits. This fits only when the requirement genuinely treats the two directions separately.
There are also two cycle models:
- Cyclic: The allowance applies to each selected cycle. Available periods are Day, Week, Month, and Year. Unused data volume does not carry over.
- Non-cyclic: The allowance applies to a single cycle period.
Quota per cycle defines the allowance for each cycle. An optional Maximum quota adds an overall limit and must be higher than the cycle quota. When the cycle or overall limit is exhausted, the firewall disconnects the user. Reset user accounting is required to reconnect before the regular reset.
For the pilot example:
- Open Profiles > Network traffic quota > Add.
- Set Name to
Students_DataVolume. - Enter, for example,
Pilot: 5000 MB per day, Owner ITas the Description. - Set Restriction to Total network traffic.
- Set Cycle type to Cyclic.
- Set Cycle period to Day.
- Set Quota per cycle to
5000 MB. - Leave Maximum quota set to Unlimited for this recurring example. If an overall limit is required, it must be higher than the cycle quota.
- Save with Save.
In this example, 5000 MB corresponds to 5 GB. In a real policy, derive the value from the approved allowance and enter it in the unit expected by WebAdmin. A separate upload/download policy instead receives its own justified value for each direction.
Assign quotas to a group or user
Use a group as the normal operating method
For users with the same allowance, a group policy is easier to operate than many individual values:
- Open Authentication > Groups.
- Create the
Quota_Pilotgroup or edit a clearly scoped pilot group. - Select
Students_InternetTimefor Surfing quota. - Select
Students_DataVolumefor Network traffic. - Do not change other access time, traffic shaping, remote access, or portal values incidentally.
- Save.
- Reauthenticate the pilot user and verify the group actually in use.
Manage Sophos Firewall user groups safely explains how local and imported groups, the main group, and user overrides interact. The actual AD import remains in Connect Active Directory to Sophos Firewall.
A user override takes precedence
Under Authentication > Users, Surfing quota and Network traffic can be set differently for an individual user. These user values take precedence over the group policy.
If a group change does not affect one user, inspect that user’s object first. An override is suitable for a documented exception or pilot, but can create hidden exceptions over time. To return to the group policy, restore the user to the previous inherited state in a controlled manner.
Only the main group counts for Active Directory
For AD users, surfing quota and network traffic do not use Other group memberships. The applicable value comes from the Main Group shown in the Group field under Authentication > Users, or from an explicit user policy.
The order under Authentication > Groups > Reorder can change the Main Group and therefore affect several policies at once. It must not be moved as a quick quota fix. After a planned group change, reauthenticate the user and verify the Main Group again.
Clientless Users are excluded
Clientless Users support neither surfing quota nor network traffic. For a fixed device without user sign-in, plan the network path, schedule, and, where needed, traffic shaping in a narrow firewall rule. User quotas are not used as an IP-based substitute.
Review consumption and validate the limit
View usage in WebAdmin
For consumption data, Sophos requires a user-based firewall rule with Log firewall traffic enabled. Then:
- Reauthenticate the pilot user.
- Verify the username and source address under Current activities > Live users.
- Open Authentication > Users and select the pilot user.
- Open View usage.
- For surfing quota, review allotted time, expiration, and consumed internet time.
- For network traffic, review Cycle renewal, upload, download, and allotted quota.
- Generate a small allowed test transfer and review the change again.
- In Log Viewer, correlate user, Source, Destination, Service, Firewall Rule ID, Action, and timestamp.
The monthly view additionally shows source IP, start, stop, duration, upload, and download. A consumption value alone does not prove that the intended path and correct rule were used. Therefore, combine View usage, Log Viewer, and a real test flow. Test a Sophos Firewall rule reliably explains the rule validation.
User-side review in the User Portal
In the User Portal, under Internet usage, a user can review allotted and consumed surfing time, cycle renewal, and upload, download, and remaining allowance depending on account type and policy. This reduces support queries but does not replace the administrator’s validation of assignment, Main Group, rule, and logs.
Test the consumption limit in a controlled manner
Use a separate pilot policy with a deliberately small but sufficient allowance for a limit test. The test must not affect a production group.
- Document the starting values in View usage.
- Start a clearly bounded HTTP or HTTPS test flow.
- Observe consumption and Log Viewer during the test.
- Confirm that reaching the limit produces the expected disconnection.
- Do not assume a second-exact transition; the firewall checks authorization periodically.
- Test the next regular cycle or an explicitly approved reset.
- Restore the pilot policy and previous assignment afterward.
Use Reset user accounting safely
Reset user accounting resets the user’s surfing time and network traffic consumption. With an exhausted network traffic quota, this reset is required if the user must reconnect before the next regular cycle.
A controlled reset is:
- Document the user, ticket, reason, current quota values, and time.
- Check whether the regular cycle change can be awaited.
- Make sure the correct user is selected.
- Open the user under Authentication > Users.
- Open View usage and preserve the starting values.
- Trigger Reset user accounting only with the intended approval.
- Reauthenticate the user and verify the new counters.
- Check a small test flow, the Firewall Rule ID, and logs.
The reset does not correct a wrong Main Group, missing user recognition, or a blocking firewall or web policy. If those causes are not resolved first, the problem returns despite the counters having been reset.
Troubleshoot systematically
The quota does not appear to count
First check whether the expected identity and source address appear under Current activities > Live users. Then verify that the traffic matches a user-based firewall rule with Log firewall traffic. If logging is missing or the flow uses another rule, View usage may remain incomplete.
Next compare the group policy, user override, and, for AD, the Main Group. Do not reduce the quota prematurely merely to force a visible effect.
A group quota affects only some users
An explicit policy on the user takes precedence. Under Authentication > Users, inspect both quota fields and the Main Group. For AD, Other group memberships are not evaluated. Reauthenticate the user after a group change.
The user is disconnected unexpectedly
Under View usage, check whether Cycle quota, Maximum quota, or Maximum access time has been reached. Then inspect Access Time, Web Policy, firewall rule, and authentication separately. A Captive Portal can also appear because of wrong credentials or other authentication issues; the quota is not automatically the cause. Set up and test the Sophos Firewall Captive Portal explains the complete sign-in path.
Consumption does not match expectations
Check whether Total network traffic or separate upload/download limits are configured. Then compare monthly details, source IP, Firewall Rule ID, and the actual test transfer. A network traffic quota counts data volume, not only visible browser downloads; background traffic from the authenticated user can also contribute to consumption.
A reset helps only briefly
If the user is disconnected again soon after the reset, inspect policy values, cycle, maximum, user override, and actual consumption. Do not reset the counter repeatedly before understanding the cause.
Rollback and operation
A controlled rollback restores the previous inheritance and counter state transparently:
- Restore the previous surfing and network traffic assignments for the pilot user or pilot group.
- For AD, reauthenticate the user and verify the Main Group.
- Document View usage and current consumption.
- Reset accounting in a controlled manner only if this was agreed for the test.
- Run a small test flow and verify the Firewall Rule ID and logs.
- Remove pilot policies only when no user or group dependency remains.
- Update the ticket, owner, limits, and test result.
In operation, every shared quota needs a clear name, a description, an owner, and a documented reason for the cycle, allowance, and overall limit. Validate changes with a pilot user, a positive consumption test, and a negative limit test.
Operational checklist
- Time consumption and data consumption were planned separately.
- Surfing quota and network traffic quota have clear names and owners.
- Cycle, Validity, Quota per cycle, and Maximum are justified.
- The policies are assigned to the correct group or user.
- User overrides were reviewed.
- For AD, the Main Group is correct; Other group memberships are not assumed.
- Clientless Users are not planned with user quotas.
- The pilot user appears as a Live User.
- The user-based firewall rule logs the test traffic.
- View usage, User Portal, Firewall Rule ID, and real consumption align.
- Reset user accounting is used only with documentation and approval.
- The previous state and rollback are documented.
Frequently asked questions
What is the difference between surfing quota and Access Time?
08:00 and 17:00; surfing quota is appropriate when, for example, two hours may be consumed within a cycle.