Sophos Firewall Sizing Guide: Properly Dimensioning an XGS Appliance
Sophos Firewall sizing is not just about the number of users. Key factors include bandwidth, TLS Inspection, IPS, VPN, HA, logging, and reserve …
Practical Sophos Firewall guides for setup, hardening, VPN, network rules, licenses, updates, logs, and troubleshooting.
The articles are organised by typical admin tasks: select, set up, secure, publish, connect remotely, analyse, and restore.
Sizing, XGS Appliance selection, Base License, bundles, Air Gap, lifecycle, portals, and license operation.
Sophos Firewall sizing is not just about the number of users. Key factors include bandwidth, TLS Inspection, IPS, VPN, HA, logging, and reserve …
Sophos offers Standard and Xstream as appliance bundles. Avanet Epic Protection adds Email and Webserver Protection to Xstream.
The Base License is the foundation of Sophos Firewall, but it does not replace support or security subscriptions. Licence status, support, updates, HA …
There are two official paths from a UTM license to SFOS. This guide separates SG conversion from virtual license migration and explains prerequisites, …
How to activate a Sophos Firewall Subscription Key and check its licence status, assignment, and synchronization.
Air-gap operation on Sophos Firewall requires approval, license file, manual synchronization, pattern updates, and a clear operational routine.
Sophos Firewall datasheet values are comparative figures. Key factors include firewall, IMIX, IPS, NGFW, TLS Inspection, VPN, and reserves.
Hardware, virtual appliance, Software Appliance and Cloud Deployment differ in operation, HA, recovery, sizing and responsibilities.
Standalone and Auto Scaling on AWS have different licensing, interfaces, traffic directions, and operating boundaries.
Azure runs Sophos Firewall as a cloud appliance. The operating model, static NIC addresses, UDRs, and symmetric return paths are decisive.
This article explains XG End of Life, XG vs XGS differences, SFOS 21/22 limits and how to prepare migration to XGS cleanly.
Sophos lifecycle planning needs End-of-Sale, Last Renewal, End-of-Life, successor products and clear checks before renewal, migration or hardware …
Warranty, support, and RMA are separate checks. The device, serial number, lifecycle, support model, and replacement process determine eligibility.
Central Admin, Self Service, Support, and firewall portals serve different purposes. Sign-in, licensing, access, and Remote Access are key …
Quick ways to find the serial number in SFOS 22 and Sophos Central, with guidance for hardware, virtual firewalls, HA, and support cases.
For hardware replacement, plan the claim, license transfer, and configuration restore separately. This workflow transfers subscriptions in Sophos …
How to safely transfer a Sophos Firewall license and account assignment to another Central account.
Setup Wizard, Central connection, Active Directory, STAS, SATC, Device Access, and support access.
After the Setup Wizard, the firewall is accessible but not yet fully hardened. Following this, backup, firmware, Device Access, rules, and logs are …
An accurate firewall clock is essential for logs, MFA, certificates, VPNs, and schedules. This guide shows how to configure and verify the time …
A Sophos Firewall can operate locally but offers additional features for management, backups, reporting, and security with Sophos Central.
Active Directory provides users, groups and authentication for Sophos Firewall. LDAPS, search base, group import, Main Group and AD SSO matter.
Groups bundle user policies but do not replace access rules. Their source, order, and Main Group determine which policy actually applies.
Sophos Firewall can authenticate users from generic LDAP directories. The key requirements are an encrypted connection, suitable search attributes, a …
A local user needs more than a username and password. Group, authentication method, service, rule, MFA, and lifecycle must work together.
Guest accounts receive time-limited credentials. A restrictive group, clear validity, a tested Captive Portal, and clean offboarding are essential.
This guide connects Sophos Firewall to a RADIUS server and covers the server object, NPS, service order, groups, validation, troubleshooting, and …
TACACS+ centralizes password verification, but the SFOS administrator role remains local. A safe rollout requires a local emergency admin, a pilot …
RADIUS SSO creates user-to-IP mappings from accounting packets. The actual sender, Framed-IP-Address, Device Access, and a controlled rule test are …
Clientless Users assign an identity to a fixed IP without a login or agent. A stable address, narrow rules, and a real negative test are essential.
STAS maps AD logons to client IPs so Sophos Firewall can use user-based rules. This guide covers setup, testing and troubleshooting.
Client Authentication Agent signs a user directly in to the firewall. The TLS-protected agent path, correct authentication method, and a real test of …
SATC maps users on Remote Desktop Session Hosts to Sophos Firewall. Server Protection, registry, Device Access and Live Users matter.
Per-Connection AD SSO identifies multiple users behind one RDS IP for each proxy connection. This guide covers selection, setup, tests, and limits.
Sophos Endpoint sends the Windows domain identity through Security Heartbeat. The firewall validates it in AD and can apply user-based rules.
Chromebook SSO maps signed-in Google Workspace users to their IP addresses. The certificate, Device Access, two firewall rules, and the managed MV3 …
Map Entra groups or app roles to local administrator profiles. A tested emergency login, least privilege, and a negative access test are essential.
Personal admin accounts replace shared logins. Profiles, MFA, schedules, and login sources limit permissions and make changes traceable.
The login disclaimer is a compliance and notice feature. It needs approved wording, separate access controls, and genuine tests for sign-in, email, …
Device Access protects local firewall services. This guide covers narrow ACL exceptions, safe rollout, proxy and port-sharing pitfalls, and targeted …
Restrict Avanet support access by task, source, permissions, and time, then validate and remove it. The guide also distinguishes Sophos Support …
Firewall rules, zones, interfaces, VLAN, NAT, DNS, DHCP, SD-WAN, NTP, and VoIP.
Zones define security areas, while interfaces connect networks. Clear assignments, restrictive Device Access and suitable firewall rules are …
Wi-Fi managed directly by SFOS requires the correct traffic assignment, a suitable client network, DHCP, firewall rules and assignment to an access …
An APX mesh extends an existing SFOS-managed wireless network without a network cable, but requires a wired root AP, one fixed common channel, and a …
A guided example for restricted guest access with vouchers and the simpler alternative using a daily password.
Clear host and service objects make firewall rules easier to understand. The key is choosing the right object type and destination port, and checking …
Captive Portal links a browser login to user rules. Device Access, DNS, authentication, HTTPS, and a clean acceptance test are essential.
Firewall rules are at the heart of Sophos Firewall. The key aspects are rule structure, order, scope, rule types, practical examples, testing and …
Schedules limit rules and policies to defined time windows. The schedule type, firewall time, rule order, and tests before and after switching are …
Access Time combines a recurring schedule with Allow or Deny. User identification, policy assignment, the AD main group, and boundary tests are …
Surfing quota limits consumed internet time, while network traffic quota limits data volume. Assignment, main group, logging, and View usage are …
A clear rule description explains its purpose, ownership and expiry date. Logs, the Rule ID and usage data then show whether the rule is still needed.
An alias IP adds an address to a physical interface. The provider path, NAT, Device Access, ARP, and a real traffic test are essential.
PPPoE only works when the provider device, VLAN, credentials, gateway, DNS, and firewall rule all match.
VLANs on Sophos Firewall need more than a VLAN ID: parent interface, switch tagging, zone, IP objects, DHCP, DNS, rules, NAT and tests must match.
A bridge inserts Sophos Firewall transparently into an existing Layer 2 path. The key requirements are correct zones and rules, independent management …
A breakout divides a fast QSFP port into two or four slower interfaces. The model, port mode, restart, and peer device must match exactly.
Legacy CLI VLAN tags on bridges disrupt firewall traffic in SFOS 22 GA and MR1 and block upgrades from MR2 onward.
A practical workflow for selecting transceivers, configuring ports, and troubleshooting a missing or unstable SFP link.
A LAG bundles two to four ports. The right bonding mode, safe migration, switch configuration, and real failover and load tests are essential.
Fail-to-Wire keeps the physical path open during power or hardware failure. Traffic then passes without firewall rules, scanning, or logs.
Proxy ARP answers ARP requests for an additional IPv4 address. Firewall rules, NAT, routing, and the return path remain separate checks.
Discover Mode analyzes mirrored network traffic without being inline. A clean SPAN port, separate management, and a clear boundary are essential: TAP …
FQDN hosts help with dynamic cloud and service destinations. Wildcard FQDNs are different because the firewall learns matching IP addresses from DNS …
A reproducible test shows whether rule order, matching, NAT, routing, user matching, or a security module affects the connection.
Captive Portal with Entra ID SSO maps local users through browser login. Redirect URI, Device Access, group matching, and logs are important.
Rule tests need clear test data and real events. Log Viewer, Policy Tester, Packet Capture, tcpdump, Central Reporting, and Syslog answer different …
IPv6 Prefix Delegation brings provider prefixes into internal networks. Key aspects include WAN configuration, Router Advertisement, rules, and …
SFOS 22 supports IPv6 for many core features, but not everywhere. Knowing the limits prevents design mistakes involving VPN, WAF, DNS, updates, and …
Router Advertisement provides IPv6 clients with a prefix, default gateway, and operating flags. A suitable /64, the correct DHCPv6 role, and a real …
NAT translates addresses or ports but does not allow traffic. The key factors are Original and Translated, rule order, routing, the return path, and …
DNAT publishes internal services through public IP addresses or ports. Narrow source restrictions, matching firewall rules, NAT order, the post-NAT …
Configure DDNS for a dynamic public IPv4 address, test it externally and resolve common provider, NAT, Multi-WAN and Cloudflare issues.
A DNS host entry answers a fixed name directly on the firewall. The actual client resolver, TTL, reverse lookup, and deliberately limited WAN …
DNS Request Routes forward selected DNS zones to internal resolvers. The actual client path, Device Access, suitable target servers, and separate …
Identify MTU and MSS issues with VPN, XFRM, SD-WAN, or PPPoE using DF tests, Packet Capture, and controlled changes.
A DHCP server on Sophos Firewall distributes IP addresses and the corresponding network settings. A clean address range, correct DNS settings and a …
A DHCPv6 server can distribute IPv6 addresses and additional parameters. Router advertisement, DUID, lease times and the real client test remain …
DHCP options distribute PXE, WDS, thin client, or RED parameters. WebAdmin, CLI fallbacks, and common error patterns are important.
DHCP Relay forwards client requests to a central DHCP server. The client interface, scope, return path, and correct IPsec variant are essential.
A static route sends a fixed destination network through a defined next hop. This example covers configuration, firewall access, testing and rollback.
A second WAN connection is initially active. For a true backup link, configure the gateway type, probe targets, activation and failback deliberately.
SD-WAN routes steer defined traffic flows through specific gateways. Narrow criteria, suitable NAT and testing with real traffic are essential.
RIP distributes IPv4 routes in small or existing networks. The decisive factors are RIPv2, narrow peer access, passive client interfaces, and real …
Configure OSPFv2 for IPv4 with an end-to-end example, advertise routes selectively, and verify neighbors; OSPFv3 is covered separately.
Set up BGP with a complete eBGP example, permit it selectively, and test it from Neighbor status through to actual packet flow.
Route precedence decides whether Static, SD-WAN or VPN takes priority. The SFOS version, competing routes and a prepared rollback are critical.
A static multicast route forwards the data stream from a known sender to fixed interfaces. The group, receiver join, and testing on both sides are …
PIM-SM dynamically connects multicast senders and receivers across multiple routers. The decisive factors are a reachable RP, correct unicast routes …
Classify missing VPN prefixes after an upgrade, use documented checks, and plan the routing architecture.
A custom gateway combines a defined next hop with health checks and SD-WAN routing. Test status, rule, return path, and actual traffic separately.
A GRE tunnel encapsulates IP traffic between two fixed endpoints. Static WAN addresses, matching tunnel IPs, routes, rules, and tests of both the …
WebAdmin IP tunnels carry IPv6 over IPv4 or IPv4 over IPv6. The tunnel type, endpoint address family, route, and return path must all match.
Central creates route-based IPsec connections between multiple firewalls. Planning, conflict resolution, and local validation remain essential.
Two CLI switches extend SD-WAN to reply packets and firewall traffic. Narrow routes, real packet tests and a documented rollback are essential.
Sophos Firewall provides the gateway, DHCP, and rules; UniFi transports the VLAN. The parent interface, port roles, NAT, and clean tests are critical.
Cellular WAN is usually a backup link. Reliable 4G/5G failover depends on the SIM, APN, PIN, gateway, signal quality, SD-WAN checks, and failback …
Sophos Firewall is not a full-fledged NTP server, but can forward NTP requests to external or internal time servers via NAT.
Classify ipsec_route correctly, capture the initial state, and route translated traffic through a policy-based tunnel in a controlled manner.
This guide explains the difference between application-based and rule-based Traffic Shaping, with specific example values and operational checks.
A safe VoIP test separates SIP from RTP, verifies the actual rule, NAT and routing path, and changes global values only with a documented rollback.
Sophos Connect, SSL VPN, Entra ID SSO, IPsec, SD-RED, and VPN troubleshooting.
Sophos Connect is a client for IPsec and SSL VPN. Protocol, platform, profile delivery, and access scope determine the right solution.
A practical firewall-side guide to Sophos Connect with IPsec Remote Access on SFOS 22—from authentication and tunnel parameters to rules, rollout and …
A .pro file automatically retrieves IPsec and SSL VPN profiles through the VPN portal. This guide explains its structure, secure deployment, GPO …
SSL VPN Remote Access only works reliably when global settings, portal, policy, current profile, DNS, MFA, Device Access, firewall rules and routing …
First document failed VPN Portal logins, then limit them with ACLs, separate ports, Login Security, identity protection, and Threat Feeds.
Clientless SSL VPN provides individual RDP, SSH, or file server connections in the browser without opening a general network tunnel.
An existing legacy IPsec configuration blocks SFOS 22 MR1. This guide covers everything from the initial assessment to a tested replacement.
L2TP remains a compatibility option for native VPN clients. This guide covers secure SFOS 22 configuration, validation, and common failures.
Sophos Connect on Windows requires the right client version, profile, platform, MFA/SSO and rules. Then verify the connection, DNS and access.
Sophos Connect on macOS depends on the client version, Apple Silicon and Rosetta, the IPsec or SSL VPN profile, DNS, MFA and tested firewall rules.
Entra ID SSO connects Remote Access with OAuth 2.0, OpenID Connect, and Entra-MFA. Key elements include Redirect URIs, groups, and Device Access.
Sophos Connect updates affect VPN profiles, platforms, MFA, SSO, helpdesk and rollback. Version checks, pilots, profile tests and known issues matter.
SSL VPN with Sophos Connect on Windows needs a current OVPN profile, VPN Portal access, MFA, client version, DNS test, profile cleanup, and matching …
SSL VPN on macOS now often uses Sophos Connect instead of Tunnelblick. The OVPN profile, Apple Silicon/Rosetta, DNS, MFA and maintenance are key.
SSL VPN on iPhone and iPad uses an OpenVPN-compatible client. OVPN profile, VPN Portal, MFA, DNS and firewall rules are important.
SSL VPN on Android requires an OpenVPN client, a current OVPN profile, VPN portal access, MFA, DNS tests, firewall rules, and device-change handling.
On Linux, SSL VPN with OpenVPN is the documented path. Sophos Connect is unavailable, and NetworkManager-strongSwan is incompatible because of …
A missing .ovpn file has different causes than a 0-byte download. This process separates policy, user, certificate, and system errors.
The old Sophos SSL VPN Client is EOL and incompatible from SFOS 20.0 MR1. Migrate its profile and startup safely to Sophos Connect.
SSL Site-to-Site connects two Sophos Firewalls in a client-server model. Roles, global SSL VPN settings, networks, APC import, rules and tests must …
This guide explains every important IPsec profile field and shows a modern and a compatible baseline for Site-to-Site VPNs.
Site-to-Site IPsec requires clear networks, profiles, gateway types, IDs, rules, routing, NAT and acceptance tests. Choose route-based or policy-based …
Two tested IPsec tunnels form a prioritized failover group. This guide explains selection, monitoring, failback, logs, and acceptance testing.
Azure Site-to-Site VPN needs Local Network Gateway, Virtual Network Gateway, matching IPsec/IKE parameters, Sophos XFRM, routes and firewall rules.
A branch full tunnel requires Any selectors, VPN before Static before SD-WAN, three targeted rules, MASQ, and a clear system-traffic decision.
AWS Site-to-Site VPN needs a customer gateway, target gateway, two tunnels, matching IPsec settings, routing and validation on both sides.
Certificate-based IPsec replaces the shared PSK with mutual trust. CA exchange, Certificate ID, peer certificate, rules and a planned renewal test are …
Overlapping IPsec networks require unique translated networks on both sides. Policy-based, route-based with selectors and Any-to-Any use different NAT …
The remote site uses one stable virtual IP; SFOS 22 translates new connections to a monitored server list.
Two any-to-any tunnels use separate XFRM paths. Monitored gateways and static routes determine primary, backup, and failback behavior.
A clear diagnostic path for IPsec problems: first tunnel establishment and the Child SA, then rules, NAT, routing, the return path, and packet flow.
set vpn contains global advanced settings. This guide explains their effect, risk, baseline, and controlled testing on SFOS 22.
This guide distinguishes rekeying from idle timeouts and network faults and shows how to safely adjust a custom IPsec profile.
Sophos SD-RED connects remote sites to the firewall. This guide covers setup, firewall rules, diagnostics, and reproducible throughput tests.
The RED mode determines the gateway, DHCP, internet path, and central control. This guide helps with the choice and shows safe functional tests.
Two Sophos Firewalls can connect through a Site-to-Site RED tunnel without RED hardware. This guide covers setup, security, and validation.
MFA, TLS Inspection, WAF, Threat Feeds, IPS, Web Protection, NDR, DNS Protection, and hardening.
FIPS mode enforces FIPS-compliant cryptography, but enabling it resets the firewall completely to factory settings.
Hardening reduces the attack surface of Sophos Firewall. Key areas are management access, MFA, updates, published services, threat feeds, logging and …
LINCE mode restricts cryptography and restarts SSH. It doesn't automatically prove that the installed SFOS build is certified.
This guide classifies all 31 Health Check findings by real risk, operational value, and optional Sophos services.
Practical guide to Sophos OTP, RADIUS and Entra SSO with a pilot group, app compatibility, password-plus-OTP, recovery and troubleshooting.
TLS Inspection provides visibility into encrypted connections, but requires CA distribution, a clear rule order, a DPI/Web Proxy decision, exclusions, …
A dedicated subordinate CA integrates Sophos Firewall with the internal PKI. The key points are a private key generated on the firewall, the correct …
TLS Inspection works without browser warnings only if clients trust the firewall CA. Important steps include download, distribution, and rollback.
XML API access on Sophos Firewall should only be allowed from defined management networks, automation systems, or integration hosts.
A stateful firewall bypass skips firewall inspection. Use it only for a narrow, time-limited test with deletion commands prepared in advance.
Web Server Protection publishes HTTP and HTTPS applications as a reverse proxy. Key points are WAF or DNAT choice, DNS, certificate, web server …
Sophos Firewall can protect WAF-published web applications with MFA from SFOS 22. Version, Authentication Policy, token rollout, testing, and …
SFOS 22 obtains Let's Encrypt certificates through HTTP-01 over IPv4. Consistent public DNS, an unobstructed port 80 path, and renewal checks are …
How to import external certificates with the correct private key and CA chain into Sophos Firewall and assign them safely to the intended service.
Certificate Revocation Lists invalidate revoked certificates before expiry. The correct CA, a current CRL, and a real service test are essential.
Saving the Default CA creates a new trust anchor. Before doing so, certificates, VPN profiles, peer firewalls, and trusting clients must be fully …
Third-Party Threat Feeds bring known malicious IPs, domains, and URLs into Sophos Firewall. Feed quality, action, logging, and controlled operation …
Sophos X-Ops Threat Feeds compare outgoing traffic with known malicious destinations. Action, visibility, logging, and narrow exclusions are crucial.
IPS requires a valid license, up-to-date signatures, and an appropriate policy in the firewall rule that actually handles the traffic. A tightly …
Sophos MDR analysts can send customer-specific IoCs to the firewall in real time. Licensing, Central integration, the local action, logging, and a …
Malware scanning only works when the firewall rule, scan engine, HTTPS decryption, exceptions, and tests are correctly aligned.
Custom IPS signatures detect your own network and application patterns. A narrow syntax, an observation-only pilot, correct IPS policy assignment, and …
Set ips changes the IPS engine firewall-wide. A baseline, focused test, and prepared rollback must precede fail-close, scan, or performance changes.
Web Protection requires an appropriate firewall rule, web policy, categories, user context, Web Exceptions, TLS visibility, QUIC decision, logging, …
DPI Engine and Web Proxy apply the same web policy on different traffic paths. The deciding factors are required proxy features, TLS decryption, and a …
URL groups collect domains for web policies and SSL/TLS inspection rules. A narrow domain scope, the correct rule, and a controlled negative test are …
NDR Essentials and NDR Active Threat Intelligence enhance Sophos Firewall with network detection. Key aspects include usage limits, operation, and …
Set up, test, and operate DNS Protection with Sophos Firewall, including internal DNS zones, endpoint limitations, and troubleshooting.
A Direct Web Proxy needs more than port 3128. A narrow pilot access, the correct rule, PAC deployment, and real proxy tests are essential.
The Device Console contains global settings for Web Proxy and Captive Portal. A baseline, focused test, and rollback come before any change.
Spoof Protection and DoS Settings harden against implausible sources and flooding. This guide explains WebAdmin thresholds, CLI policies, order, tests …
IPv6-only clients reach IPv4 web destinations through Direct Web Proxy. Two separate rules and a genuine A-only test are essential.
A parent proxy requires web proxy mode and different rules depending on its location. A narrow pilot, the correct NAT path, and real positive and …
service-param extends protocol inspection to additional ports but doesn't replace a firewall service or the matching web, TLS, or mail policy.
Country blocking, Black Hole DNAT, WAF Blocked countries, and Threat Feeds serve different purposes. Rule position, local services, and monitoring are …
Application Control detects applications beyond ports alone. The key factors are a narrowly scoped Application Filter, the firewall rule that actually …
Allow and log GenAI applications in a pilot group first, then block them selectively. This guide separates Application Control, Synchronized …
Zero-Day Protection analyses suspicious downloads and email attachments. Firewall rule, web and mail path, TLS visibility, reports, exceptions and …
This guide covers the mail flow and MX record, the MTA policy, validation, and troubleshooting without overlooking relay, TLS, or DKIM risks.
This guide connects the SPX template, trigger, password delivery, and Reply Portal into a controlled workflow for encrypted outbound email.
This guide combines the existing SMTP path with transparent proxy scanning, tightly scoped NAT and firewall rules, and reliable end-to-end validation.
Web Exceptions can bypass decryption, certificate validation, malware scanning, zero-day analysis, or policy checks. A narrow match, positive and …
This guide connects digest delivery with the user portal, quarantine area, and user assignment and shows how to test the complete release path.
This guide combines POP/IMAP settings, TLS trust, an optional scan policy, and a firewall rule into a controlled mail retrieval test.
Web categories and instant alerts assist in web policy control. Key aspects include usage, prerequisites, configuration, logging, and error patterns.
This guide shows how to correct a confirmed false positive with one tightly scoped email exception without disabling the remaining mail protection.
This guide connects Exchange Online and Sophos Firewall in a controlled bidirectional mail flow with tight relay access and reliable validation.
In SFOS 22, Block QUIC protocol drops outbound UDP 80 and 443 within the firewall rule's scope. Verify TCP fallback, Rule ID, web/TLS effect, and a …
The appropriate Device Console commands for WebAdmin, User Portal, and global or VPN-specific settings.
Log Viewer, service logs, audit trail, SSH, CLI, packet capture, tcpdump, syslog, and SIEM.
For troubleshooting, know which Sophos Firewall service belongs to which module, which log file fits, and when Log Viewer, CTR, debug, or CLI is …
Log Viewer shows logged firewall decisions. This guide explains filters, fields, timing, limitations, and safe correlation.
If no new events appear in Log Viewer, first check the view, logging, and packet flow. The old Garner workaround does not apply to SFOS 22.
In cases of disruptions, VPN issues, or unclear firewall events, a support case requires clean logs, timestamps, and captures if necessary.
Configuration Audit shows which administrator changed supported firewall objects, when the change occurred, and what was modified.
SSH is a powerful support channel on Sophos Firewall. Device Access, ACL exceptions, public keys, host keys and control limits matter.
Essential CLI commands support log analysis, network checks, service status, and debug logging. A controlled workflow is what makes them useful.
Sophos Firewall needs its own outbound connections to Sophos services. Current FQDNs, DNS, NTP, routing, egress rules, and a targeted test for each …
Check the SFOS 22 list, assess port sharing, and make a port change with validation and a reliable rollback.
SFOS loads several protocol helpers by default. Changes are global and require a status check, a test flow and an exact rollback.
Live Connections groups active sessions by application, source IP address, or user, while Connection List shows individual sessions. This guide …
This guide shows how to capture a single flow in WebAdmin and identify where packets arrive, are forwarded, or are dropped.
tcpdump provides precise packet captures on the firewall. This guide separates Device Console and Advanced Shell and covers filters, PCAP, analysis, …
A successful server test doesn't prove that a user can sign in. This workflow separates the service, identity, group policy, and subsequent traffic …
Sophos Firewall uses the internal ID range through 65535 for users and groups. The specific ID shows whether authentication or VPN Portal problems are …
AD SSO can fail after certain upgrades to SFOS 22.0 GA. A log entry narrows down the issue before a targeted NASM rebuild.
A compact diagnostic workflow for drops: reproduce traffic, correlate Log Viewer and Packet Capture, then check rules, NAT, return path, and security …
Sophos Firewall may drop Accurate ECN as Invalid TCP reserved bit. Diagnosis, global CLI workaround, and a safe return to strict-policy on.
The Device Console groups global firewall parameters for packet inspection, TCP, UDP, and special paths. A baseline, narrow test, and rollback are …
The neighbor cache maps IPv4 and IPv6 addresses to MAC addresses. This guide shows how to check stale entries, relearn them, and safely use static …
A safe Wireless Controller workflow: read and narrow down first, capture only what is needed, and restore every temporary value.
After a firewall replacement, old ARP entries can block individual WAN or alias IP addresses. Packet Capture separates ARP from NAT and rule issues.
Missing Heartbeat means that the firewall continues to see traffic but no longer receives a matching Security Heartbeat. Scope, path and timing are …
Synchronized Application Control data should not be cleaned up using public PostgreSQL commands. This guide covers diagnosis, evidence collection, and …
The Control Center widget combines endpoint, user, file, TLS, and session signals. This guide explains their meaning, drill-downs, safe changes, …
iPerf3 measures throughput over a defined path. The test becomes meaningful with a baseline, clear direction, narrow firewall rule, and proper …
The sensor view and hardware log show host CPU, NPU, and fan values. Model limits, trends, load, rack temperature, and symptoms determine the …
sFlow makes traffic patterns and noticeable flows visible. Important aspects include Collector, Sampling, Interface Selection, Limits, and Operational …
Set up SNMPv3 securely on Sophos Firewall, test it with snmpget and snmpwalk, and correctly interpret the SFOS 22 hardware metrics.
NetFlow exports metadata from logged rule connections to an external collector. The key requirements are v5 compatibility, the UDP path, data …
The daily admin checklist combines current system status, trends, security events, and documented escalation without turning a single spike into a …
A speed test on the Sophos Firewall helps isolate WAN and client issues. Key aspects include SSH testing, WAN path, unit, test file, and …
The mail server and event selection are separate settings. Only a delivered test email and a real selected event confirm the complete alert path.
Data Anonymization encrypts usernames, IP, MAC, and email addresses in logs and reports. At least two authorizers and real output tests are important.
Scheduled on-box reports send local analyses daily or weekly as a PDF. Report selection, mail transport, functional testing, and content review are …
Central Firewall Reporting transfers firewall logs to Sophos Central. Important aspects include log selection, retention, Report Hub, and syslog …
How to send the right Sophos Firewall logs reliably and securely to a Syslog server, SIEM, or SOC.
Backup, firmware, SFOS upgrades, task queue, services, Config Studio, reimage, SSD, HA, and RMA.
Backups require the file, password, Secure Storage Master Key, target version, management access, and restore compatibility. Essential before updates, …
A selective configuration import adds or overwrites objects, but isn't a restore. Dependencies, SSMK, compatibility, and real tests are decisive.
A compact go/no-go checklist for the upgrade path, recovery, HA, Central scheduling, and technical validation after a firmware update.
How to download and install a suitable SFOS image and verify the firewall with real functional tests after the restart.
SFLoader replaces corrupt firmware when WebAdmin is no longer accessible. This recovery path doesn't apply to XGS Appliance, overwrites a firmware …
Some older virtual Sophos Firewalls require a larger Primary Disk and adjusted partitions before SFOS 22.
The most important blockers and checks before an upgrade to SFOS 22.
Manage multiple Sophos Firewalls with one group policy without overwriting local configurations without control.
Distinguish both queues, use Retry, Skip, and Force sync deliberately, and verify the result on the firewall.
SFOS 23 no longer supports the native eDirectory server type. This runbook covers target selection, parallel operation, group validation, cutover and …
Pattern updates keep protection signatures, engines and device firmware current. This guide covers automation, status, manual updates and …
Export complete or selective firewall configurations via the Sophos Central REST API, verify them, and import them in a controlled manner.
SFOS waits 3 seconds by default for a ready USB drive. Increase the value only for a confirmed detection problem and test again.
Restarting a service can recover an individual firewall module. The correct service, secure access and a real functional test are essential.
Config Studio makes firewall configurations readable, compares multiple versions and prepares changes or migrations.
The documented recovery method for physical appliances resets only the default admin password. Option 4, HA, and the follow-up checks are essential.
If only WebAdmin stops responding, tomcat and apache can be checked and restarted individually. Different requirements apply to HA.
After an unplanned restart, first preserve uptime, build, HA role, and logs. Then distinguish between software, load, power, hardware, and VM causes.
A factory reset removes the custom configuration but not all local data. Backup, recovery access, and the exact XGS Appliance model must be known …
Preserve the failsafe message and system state first. The platform, HA role, and firmware build then guide a safe decision between correction and …
A reimage fully overwrites the firewall. Before starting, backup, SSMK, installer image, restore compatibility, HA and post-checks matter.
A read-only smartctl query can show the endurance raw value on a physical XGS Appliance. The device path, attribute, and threshold remain …
Storage warnings require root-cause analysis. /var, reports, event logs, troubleshooting logs, mail queue, warning thresholds and data retention are …
HA connects two Sophos Firewalls into a cluster. Important aspects include prerequisites, licensing, HA link, Monitored Ports, QuickHA, updates, RMA …
Custom cron jobs and startup scripts are not part of the normal SFOS operating model. This guide explains supported alternatives and a safe migration …
Since July 2026, Sophos Support Assistant guides troubleshooting and case creation. Good preparation remains essential for an efficient support case.
A clear Sophos RMA process: isolate the fault, secure data and backups, open a support case, check the replacement and meet the return deadline.
Special cases, older clients, and topics that do not fit neatly into the main areas.
Home Edition, an XGS Appliance with a Base License, and Sophos Home suit different personal scenarios. Understand their limits, benefits, and …
L3 adoption requires TCP 8080 from the UniFi device to the controller and a valid Inform URL. DNS, SSH, and DHCP Option 43 are explained with …