Thursday, July 24, 2025
Sophos Firewall: Verify if the hotfixes for CVE-2025-6704 CVE-2025-7624, CVE-2025-7382, CVE-2024-13974, and CVE-2024-13973 have been applied
Thursday, December 14, 2023
Sophos Firewall failed to access web admin console after upgrade from SFOS 19.0.3 MR-3-Build517 to SFOS 19.5.3 MR-3-Build652
Sophos Firewall failed to access web admin console after upgrade from SFOS 19.0.3 MR-3-Build517 to SFOS 19.5.3 MR-3-Build652
Saturday, June 11, 2022
Sophos firewall model compare with Hillstone/H3C/Huawei/Sangfor
| Brand | Model | Hillstone (E series) | Hillstone(A series) | H3C | Huawei | Sangfor |
| Sophos | XGS 3100 | E5568 | SG-6000-A3700 | H3C SecPath F5030 | USG6620E | NGAF M5800 |
| Sophos | XGS 3100 | E3965 | SG-6000-A2800 | H3C SecPath F1070 | USG6610E | NGAF M5600 |
| Sophos | XGS 2100 | E3965 | SG-6000-A2700 | H3C SecPath F1070 | USG6575E | NGAF M5400 |
| Sophos | XGS 5500 | E5960 | SG-6000-A5200 | H3C SecPath F5060 | USG6610E | NGAF M6000 |
| Sophos | XGS 136 | E3662 | SG-6000-A2000 | H3C SecPath F1070 | USG6585E | NGAF M5300 |
Sophos firewall model compare with Hillstone/H3C/Huawei/Sangfor
Tuesday, March 29, 2022
Sophos Firewall: Verify if the hotfix for CVE-2022-1040 is applied on your Sophos XG firewall
Given the "Allow automatic installation of hotfixes" feature enabled (it is enabled by default). First come first is check this setting is it enabled.
Then, you need to verify the hotfix is it install by access the advanced shell by using SSH client remotely login your firewall or via console access
- Select "5" – Device Management
- Select "3" – Advanced Shell
- Enter the following command:
test -f /static/up_mode_json_stamp && echo "Hotfix is applied" || echo "Hotfix isn't applied"
If the hotfix is applied, the return is "Hotfix is applied"
Enter "Exit" to exit the shell mode.
Reference:
Accessing Command Line Console - Sophos Firewall
Sophos Firewall: Verify if the hotfix for CVE-2022-1040 is applied
Sophos Firewall: Verify if the hotfix for CVE-2022-1040 is applied on your Sophos XG firewall
Thursday, February 3, 2022
How to enable IPv6 native mode on Sophos SG UTM
- Enable IPv6
- Enter IPv6 fixed IP address , Netmask and Default GW address on WAN Interface
- Add IPv6 address to Internal
- Add Prefix Advsetis….. to intermal
You should able to see the WAN IP of IPv6
Test:
Go to "Support" -> "Tools"
Internal IPv6 address: fda8:06c3:ce53:a890:0000:0000:0000:0004 (Unique Local )
- enable IPv6
- force the UTM to request a prefix (not sure why I needed to do it)
- add <prefix>00::1 as the IP address on the LAN interface (64-bit mask)
- advertise the prefix on the LAN interface using stateless integrated server
- enable automatic renumbering
Reference:
https://www.sysorchestra.com/configuring-ipv6-with-sophos-utm-9-and-kabeldeutschland/
https://simpledns.plus/private-ipv6
http://www.steves-internet-guide.com/ipv6-guide/
https://www.jannet.hk/zh-Hant/post/IP-Address-Version-6-IPv6/
How to enable IPv6 native mode on Sophos SG UTM
Sunday, November 24, 2019
Allow Bitdefender updates via Sophos XG firewall
Under Web -> Exception
Create the following rules
https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/109202/anyone-else-having-issues-with-bitdefender-updates
Allow Bitdefender updates via Sophos XG firewall
Thursday, September 26, 2019
Allow Galaxy Apps Store Update via Sophos XG firewall
Tuesday, August 13, 2019
Sophos XG firewall–many website have “Security Risk Detected” while accessing HTTPS sites suddenly on 10 Aug 2019
Workaround solution: Change the antivirus engine from Sophos to Avira
Reference:
Sophos XG firewall–many website have “Security Risk Detected” while accessing HTTPS sites suddenly on 10 Aug 2019
Monday, July 1, 2019
Sophos SG UTM - SSL VPN configuration change need to request client to download an installation file to update the client configuration
Sophos SG UTM - SSL VPN configuration change need to request client to download an installation file to update the client configuration
Sophos SG UTM – SSL VPN
Sophos VPN change profile name
If you want to change the VPN profile name, go to “Program Files (x86)”\Sophos\Sophos SSL VPN Client\config, change those config file name
Sophos SG UTM – SSL VPN
Sophos XG Firewall rules - Proxy - Direct mode only
Create a new service “Proxy”
TCP
Source Port 1:65535
Destination Port 3128
UDP
Source Port 1:65535
Destination Port 3128
Reference:
https://community.sophos.com/kb/en-us/125585
https://community.sophos.com/kb/en-us/122802
https://community.sophos.com/kb/en-us/123522
Sophos XG Firewall rules - Proxy - Direct mode only
Sophos XG firewall upload speed slow - workaround - set Intrusion Prevention (IPS) from LAN to WAN to None (On the LAN to WAN firewall rules)
Sophos XG firewall upload speed slow - workaround - set Intrusion Prevention (IPS) from LAN to WAN to None (On the LAN to WAN firewall rules)
Sophos XG firewall allow Google update
Sophos XG Home firewall
Recommended hardware: 研凌n13 i3 7100 i5 7200u 3855U/3865u软路由主机lede小型工控机linux esxi迷你主机小电脑无线千兆网卡6口
i3, 6GB RAM is good enough. (Remark: Home edition limited to 6GB RAM max)
Sophos UTM free edition is not good for home since it remove the web filtering features
If you use 2GB only, the memory usage will be very high (Tested on 17.1)
6GB memory usage will below 50%
It can block many attack at gateway level:
Performance also OK:
Sophos XG Home firewall
Saturday, December 29, 2018
Sophos SG UTM and XG Firewall
Astaro Security Gateway has been renamed Sophos UTM (Sophos SG)
Cyberoam become Sophos XG
Microsoft Internet Security and Acceleration (ISA) server 2000, 2004, 2006 or a Microsoft Forefront Threat Management Gateway (TMG) server 2010 EOL, one of the option are using Sophos SG UTM as a replacement.
Sophos SG UTM – Traditional Firewall comes with full coverage security function.
Sophos XG – Next Generation Firewall (NGFW) comes with full coverage security function PLUS heart-beat function, heat beat means firewall can be communicates with Client PC to stop threat exposure.
UTM: Unified Threat Management
NGFW: Next Generation Firewall
Sophos SG UTM and XG Firewall
Thursday, December 27, 2018
Allow Microsoft Windows Update (Windows 10) pass-thru Sophos XG Firewall proxy (SFOS 17.1)
Add the following exclusion URL under Microsoft Windows Updates exception list:
^([A-Za-z0-9.-]*\.)?tlu.dl.delivery.mp.microsoft\.com/
^([A-Za-z0-9.-]*\.)?au.windowsupdate\.com/
^([A-Za-z0-9.-]*\.)? download.windowsupdate\.com/
Reference:
https://docs.microsoft.com/en-us/windows/deployment/update/windows-update-troubleshooting
Allow Microsoft Windows Update (Windows 10) pass-thru Sophos XG Firewall proxy (SFOS 17.1)
Allow Kaspersky Update pass-thru Sophos XG Firewall proxy (SFOS 17.1)
Add the exceptions policy, ^([A-Za-z0-9.-]*\.)?geo.kaspersky\.com/
Reference:
https://support.kaspersky.com/6105
Allow Kaspersky Update pass-thru Sophos XG Firewall proxy (SFOS 17.1)
Create firewall service for proxy only on Sophos XG Firewall (SFOS 17.1)
You need to Add TCP and UDP from ALL Source Port to Destination Port which is your proxy server for connect
Create firewall service for proxy only on Sophos XG Firewall (SFOS 17.1)
Saturday, November 24, 2018
Sophos XG - SFOS 17.1.4 MR4 Released
If you are running on 17.1.3 MR3, please upgrade asap.
It fix many connectivity issues via proxy such as Windows 10 update failed, Kaspersky update failed…..
Since it just released, you need to download it manually.
https://community.sophos.com/products/xg-firewall/b/xg-blog/posts/sfos-17-1-4-mr4-released
Reference:
https://community.sophos.com/kb/en-us/132229
https://community.sophos.com/kb/en-us/123285
Sophos XG - SFOS 17.1.4 MR4 Released
Friday, August 31, 2018
Sophos SSL VPN client change profile name
1. Go to C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config
2. Change the file name of the profile
Sophos SSL VPN client change profile name






