Skip to content
Avanet

Sophos Security Heartbeat and Synchronized Security

Security Heartbeat connects the security state of a Sophos Endpoint to a compatible Sophos Firewall. The products remain separate: Endpoint detects and assesses device health, while the Synchronized Security settings use that state for the configured network response.

This product boundary also explains C2/Generic-C: a Sophos Firewall detects and blocks the connection to a known malicious destination and reports the result to the Endpoint through Heartbeat. The Endpoint shows the Health or Event state but is not the primary detection source. Therefore look for the process and destination in the Firewall’s Security Heartbeat report or Network & Threats reports.

What Heartbeat reports

A managed Endpoint reports its Health State through Sophos Central. A Sophos Firewall connected to the same Central account can associate this state with specific devices and use it in rules or automated responses.

A red state does not automatically block every network connection. The actual behaviour depends on Firewall rules, the minimum Heartbeat requirement and configured Synchronized Security exclusions.

HeartbeatTypical meaning
GreenProtection is working, with no active or inactive malware and no PUA reported
YellowInactive malware or a PUA requires assessment
RedActive or uncleaned malware, malicious network traffic or faulty protection software

The colour is a routing signal. Investigate the specific cause in the Endpoint status and alert.

Requirements

  • Endpoint and Firewall are connected to the correct Sophos Central account.
  • Licences and supported versions are active.
  • DNS, time, internet communication and certificate validation work.
  • The device is unique and current in Central.
  • Firewall rules use Heartbeat deliberately rather than inadvertently across the tenant.

Before activation, document which destinations devices with a yellow or red state may still reach. Management, remediation and support access must not accidentally become impossible.

Reject connections to unsafe devices

Under Global Settings > Protection and Remediation > Synchronized Security, devices can be configured to reject connections to or from systems with red Health or a missing Security Heartbeat.

The information is distributed to other devices on the same subnet. These devices log, for example, that access to or from an unsafe device was denied. The rejected state cannot be overridden locally; the affected system must return to a healthy state.

Critical servers can be excluded explicitly. Update Caches and Message Relays are excluded by default so remediation and management remain available. Keep exclusions narrow, because an excluded critical server with red Health can otherwise continue communicating freely.

Handle spam and virus sending

With Sophos Endpoint and Sophos Email, Synchronized Security can scan the devices of a mailbox owner when at least five messages classified as spam or containing viruses are sent within ten minutes.

The mailbox is blocked initially for one hour. Repeated triggers double the blocking period; after six triggers, a permanent block requires Sophos Support. Disabling the Synchronized Security option turns off only the Endpoint scan, not the mailbox block applied by Sophos Email.

Use this email workflow only when both products are licensed and the mailbox user is associated correctly with their devices.

Pilot and test

  1. Define a test Endpoint and test rule.
  2. Confirm a healthy Heartbeat and normal connectivity.
  3. Trigger a controlled Health change or Sophos test case.
  4. Compare the Central status, Firewall Log and rule effect.
  5. Verify remediation access and return to green.
  6. Simulate missing or stale Heartbeats.

Use an EICAR test only in an approved lab environment. Do not distribute it by email or on production shares.

Troubleshooting

If Central shows a different state from the Firewall, check timestamps, device identity, Central association, internet communication and Firewall Logs. Duplicate device objects or the wrong Central tenant can prevent association.

For unexpected blocking, first determine whether the Synchronized Security setting or a normal Firewall rule triggered it. Then correct the cause; a global exclusion is rarely the right first action.

After a Firewall upgrade, a blocking loop can occur: the rule blocks clients without a Heartbeat, so they can no longer reach DNS or Central and cannot retrieve the new Heartbeat certificate. Only when this exact condition is confirmed, suspend Block clients with no heartbeat as narrowly and briefly as possible until DNS, Central communication and certificate retrieval work again. Then reactivate the rule and verify the Heartbeat of every affected device.

Product boundary

This article explains the Endpoint side and the interaction. Firewall rule design and Firewall Logs belong to Sophos Firewall configuration and are not treated as an Endpoint policy. Active Threat Response, also visible in Central for AP6 access points and Sophos Switches, is a different product function and is not part of this article.

Frequently asked questions

Does a red Heartbeat automatically block the network?

Not universally. The configured Firewall rules and Response functions determine the actual effect.

Can a rejected device be allowed again locally?

No. It must return to a healthy Heartbeat state or be handled centrally as a justified server exclusion.