Skip to content
Avanet

Sophos Security Heartbeat and Synchronized Security

Security Heartbeat sends the health state of a managed Sophos Endpoint to a registered Sophos Firewall. This alone doesn’t isolate everything: a matching firewall rule or the endpoint feature Reject connections from other devices must apply the network response.

Keep three mechanisms separate:

  • Security Heartbeat: health and identity exchange between Sophos Endpoint and Sophos Firewall. The firewall can use it to control source and destination access.
  • Synchronized Security: the umbrella term for responses that use Heartbeat information. These include firewall rules and Central-distributed rejection of unsafe devices on the same subnet.
  • Active Threat Response (ATR): isolates devices identified by external API users or MDR/XDR analysts through managed Sophos Switches and AP6 access points. It is neither a Heartbeat colour nor endpoint isolation.

Requirements and activation

Sophos specifies three requirements: a Sophos Central account, a trial or full licence for at least one Central-managed endpoint, and a Network Protection subscription on the firewall. Endpoint and firewall must belong to the same organisation in the correct Central tenant.

Register the firewall in WebAdmin under System > Sophos Central. After successful registration, SFOS automatically enables Security Heartbeat and Synchronized Application Control. However, A new firewall has been successfully registered to Sophos Central under My Products > Firewall Management > Firewalls confirms registration only, not the Heartbeat of a specific endpoint or a rule’s effect. See Connect Sophos Firewall to Sophos Central for the complete registration workflow.

Each endpoint receives a certificate from Sophos Central. Central shares the certificates with the firewall so it associates only endpoints from its organisation. Endpoint and firewall use an encrypted TLS connection over 52.5.76.173 and TCP 8347; reachability of the IP and port alone doesn’t prove correct tenant or certificate association.

Interpret Heartbeat states correctly

An endpoint sends its state to the firewall every 15 seconds. On first connection, it also sends network interfaces and signed-in users. The colour indicates urgency but doesn’t replace investigation of the specific alert.

StateMeaning and next step
GreenProtection software works; no active or inactive malware and no PUA is reported. Validate the baseline and normal access.
YellowFor example, a PUA, inactive malware, or no signature update for 24 hours. Review the alert; this may be temporary.
RedFor example, active or uncleaned malware, malicious network traffic, or faulty protection software. Investigate the alert and device immediately.
MissingThe firewall still sees network traffic but hasn’t received three consecutive Heartbeats. Treat this first as a communication or association state, not automatically as malware.

A network alert such as communication with a known bad host can therefore cause a red state. Use the specific event and related report to establish whether Sophos Endpoint, Firewall, or another protection component produced the original detection; the colour alone doesn’t prove the detection source.

Choose the network response deliberately

Control access in the firewall rule

Heartbeat controls are on Sophos Firewall under Rules and policies > Firewall rules > [rule] > Configure Synchronized Security Heartbeat. The fields have different purposes:

  • Minimum source HB permitted requires at least Green or Yellow for the source. No restriction also allows Red or devices without a Heartbeat.
  • Block clients with no heartbeat handles source devices without a Heartbeat.
  • Minimum destination HB permitted checks internal destinations; Sophos doesn’t apply destination Heartbeat to destinations in the WAN zone.
  • Block request to destination with no heartbeat handles internal destinations without a Heartbeat.

A device that has never sent a Heartbeat remains allowed by default. Sophos states that it is covered only when both Block clients with no heartbeat and Block request to destination with no heartbeat are enabled. A web exception that skips Policy checks can also allow web requests despite Block clients with no heartbeat.

Put Heartbeat conditions in a narrowly scoped pilot rule for genuinely managed Sophos endpoints. Printers, guests, IoT systems, and devices with third-party EDR need their own rule design rather than ever broader exceptions. See Plan Sophos Firewall rules safely for the general design.

Reject lateral connections at the endpoint

In Sophos Central, open the Global Settings icon, then Protection and Remediation > Synchronized Security. Under Reject connections from other devices, Allow devices to reject connections from other devices with red health enables the endpoint response. It applies only to devices connected to Sophos Firewall.

For Red or Missing, Sophos informs the other managed devices on the same subnet about the unsafe device. The destination endpoint logs Access request from computer denied because it may be unsafe; in the other direction it logs Access to computer denied because it may be unsafe. This local rejection can’t be overridden on the affected device. Access returns when the device becomes healthy.

You can centrally exclude critical servers. Update Caches and Message Relays are excluded from this mechanism by default so updates and communication paths remain available. Every additional exclusion increases the freedom of movement of a red server and therefore needs an owner, rationale, and review date.

Spam and virus sending is a Sophos Email workflow

Scan computers that send spam or viruses on the same Central page requires both Sophos Endpoint and Sophos Email licences. Sophos Email responds when at least five messages classified as spam or containing viruses are sent from a mailbox within ten minutes: it identifies the owner and assigned devices, blocks the mailbox initially for one hour, and starts an on-demand scan on those devices.

Each new trigger after the preceding block expires doubles the duration. After six triggers, the mailbox is blocked permanently and Sophos Support must handle the case. Turning off the Synchronized Security option stops only the endpoint scan, not the mailbox block. Check the Email event, user-to-device association, and endpoint scan separately.

Pilot and acceptance test

  1. Select one Central-managed test endpoint and a narrowly scoped firewall rule. Document normal access, required remediation destinations, and an independent admin path first.
  2. In Sophos Central, check the computer’s current health and events from the same period. On the firewall, check the relevant counter under Control Center > User & device insights > Security Heartbeat; when all endpoints are green, the detail view doesn’t list individual endpoints.
  3. Enable logging on the matching rule and run an allowed test flow from the healthy endpoint. Record source IP, destination, Rule ID, and time.
  4. Use an approved Sophos test case; don’t stop the agent, tamper with protection, or use production malware. Test Sophos Endpoint protection features describes safe methods.
  5. Compare the Central alert, endpoint event, Heartbeat view, and firewall log for the same time window. Only the explicitly configured response may take effect.
  6. After cleanup or the end of the test, confirm that the endpoint returns to Green and normal access returns. Only then expand scope.

Troubleshoot by symptom

  • Missing instead of Green/Yellow/Red: Check zone, network path, adapter changes, VPN/NAT, timestamps, and Central association first. Follow Troubleshoot Missing Heartbeat alerts for the complete workflow.
  • Central and firewall show different states: Compare the same device and time window. Check registration, endpoint online state, certificate/Central communication, and firewall and endpoint events. Don’t “fix” it by deregistering or adding global exclusions.
  • Unexpected blocking: Either endpoint message quoted above identifies Reject connections from other devices. A firewall log with Rule ID and a Heartbeat condition identifies the rule. Correct the cause and scope next.
  • Delay in a switched network or over LAG: Sophos documents a supported detection delay in Device Console for this case. Record the current value and rollback before any change; don’t set it speculatively.
  • Two endpoints use the same dock or USB interface: SFOS 22.0 MR2 Build 546 fixes false Missing Heartbeat reports under NC-176012. Correct the firmware level on older SFOS 22 builds instead of only raising a timer.
  • Cause remains unclear: Collect the time window, endpoint ID, health/event extract, firewall Rule ID, IP/MAC, affected interfaces, and an SDU. The Sophos KBA for Minimum Escalation Requirements for Endpoint Health identifies the support evidence; Self Help and SDU explains safe collection.

Distinguish Active Threat Response and endpoint isolation

Central ATR under Global Settings > Protection and Remediation > Allow and Block > Network > Active Threat Response applies to Sophos Switches and AP6 access points. External API users or MDR/XDR analysts can isolate identified MAC addresses through these network devices. On AP6, ATR overrides the MAC Filtering Allowed list configured on SSIDs.

This is a different control path from a Heartbeat firewall rule, lateral endpoint rejection, or manual endpoint isolation. To isolate and safely release an individual endpoint during an investigation, follow Isolate an endpoint and inspect it with Live Response. An ATR state in the network view proves neither a red Heartbeat nor an endpoint action.

Frequently asked questions

Does a red Heartbeat automatically block the entire network?

No. The effect depends on the matching firewall rule or the separately enabled endpoint feature Reject connections from other devices. Each has its own scope and logs.

Can Microsoft Defender send a Sophos Security Heartbeat?

No. Security Heartbeat requires a Sophos Central-managed endpoint running Sophos Endpoint Protection. Devices with third-party EDR need a separate access and segmentation design.

Is Active Threat Response the same as endpoint isolation?

No. The Central ATR path described here isolates MAC addresses through Sophos Switches and AP6 access points. Endpoint isolation is a separate response action on the managed endpoint.

Official sources