Showing posts with label XG Firewall. Show all posts
Showing posts with label XG Firewall. Show all posts

Tuesday, March 29, 2022

Sophos Firewall: Verify if the hotfix for CVE-2022-1040 is applied on your Sophos XG firewall

Given the "Allow automatic installation of hotfixes" feature enabled (it is enabled by default). First come first is check this setting is it enabled.

 

 

Then, you need to verify the hotfix is it install by access the advanced shell by using SSH client remotely login your firewall or via console access

 

  1. Select "5" – Device Management

 

  1. Select "3" – Advanced Shell

  1. Enter the following command:

 

test -f /static/up_mode_json_stamp && echo "Hotfix is applied" || echo "Hotfix isn't applied"

 

 

If the hotfix is applied, the return is "Hotfix is applied"

 

Enter "Exit" to exit the shell mode.

 

Reference:

Accessing Command Line Console - Sophos Firewall

Sophos Firewall: Verify if the hotfix for CVE-2022-1040 is applied

 

Print Friendly and PDF
Share/Bookmark

Sunday, November 24, 2019

Allow Bitdefender updates via Sophos XG firewall

Under Web -> Exception

Create the following rules

clip_image001

https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/109202/anyone-else-having-issues-with-bitdefender-updates Print Friendly and PDF
Share/Bookmark

Thursday, September 26, 2019

Allow Galaxy Apps Store Update via Sophos XG firewall

image


Reference:

https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/94745/unable-to-update-samsung-phone-behind-xg#pi2151filter=answers&pi2151scroll=true

Print Friendly and PDF
Share/Bookmark

Tuesday, August 13, 2019

Sophos XG firewall–many website have “Security Risk Detected” while accessing HTTPS sites suddenly on 10 Aug 2019


Many_https_website have error like the following suddenly

Workaround solution: Change the antivirus engine from Sophos to Avira

Solution_1

Reference:

https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/104624/security-risk-detected-while-accessing-https-sites

Print Friendly and PDF
Share/Bookmark

Monday, July 1, 2019

Sophos XG Firewall rules - Proxy - Direct mode only

Proxy

Create a new service “Proxy”

TCP

Source Port 1:65535

Destination Port 3128

UDP

Source Port 1:65535

Destination Port 3128

Proxy_2


Reference:

https://community.sophos.com/kb/en-us/125585

https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/94552/how-can-i-set-up-web-access-via-proxy-port-only

https://community.sophos.com/kb/en-us/122802

https://community.sophos.com/kb/en-us/123522 Print Friendly and PDF
Share/Bookmark

Sophos XG firewall upload speed slow - workaround - set Intrusion Prevention (IPS) from LAN to WAN to None (On the LAN to WAN firewall rules)

IPS

Print Friendly and PDF
Share/Bookmark

Sophos XG firewall allow Google update


image


https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/91948/google-play-store-blocked-by-ips

Print Friendly and PDF
Share/Bookmark

Sophos XG Home firewall

Recommended hardware: 研凌n13 i3 7100 i5 7200u 3855U/3865u软路由主机lede小型工控机linux esxi迷你主机小电脑无线千兆网卡6口

https://m.intl.taobao.com/detail/detail.html?id=555831051793&spm=a21pv.7626635.1563.d0&main_itemid=556708160706&go_item_id=555831051793&scm=1007.11563.113736.&pvid=4e98c97a-493d-46b9-b4c5-e5eb78110eed

i3, 6GB RAM is good enough. (Remark: Home edition limited to 6GB RAM max)


Sophos UTM free edition is not good for home since it remove the web filtering features


If you use 2GB only, the memory usage will be very high (Tested on 17.1)

2GB

6GB memory usage will below 50%

6GB

It can block many attack at gateway level:

image

Performance also OK:

image

Print Friendly and PDF
Share/Bookmark

Saturday, December 29, 2018

Sophos SG UTM and XG Firewall

Astaro Security Gateway has been renamed Sophos UTM (Sophos SG)
Cyberoam become Sophos XG


Microsoft Internet Security and Acceleration (ISA) server 2000, 2004, 2006 or a Microsoft Forefront Threat Management Gateway (TMG) server 2010 EOL, one of the option are using Sophos SG UTM as a replacement.


Sophos SG UTM – Traditional Firewall comes with full coverage security function.

Sophos XG – Next Generation Firewall (NGFW) comes with full coverage security function PLUS heart-beat function, heat beat means firewall can be communicates with Client PC to stop threat exposure.


UTM: Unified Threat Management

NGFW: Next Generation Firewall

Print Friendly and PDF
Share/Bookmark

Thursday, December 27, 2018

Allow Microsoft Windows Update (Windows 10) pass-thru Sophos XG Firewall proxy (SFOS 17.1)

image


Add the following exclusion URL under Microsoft Windows Updates exception list:

^([A-Za-z0-9.-]*\.)?tlu.dl.delivery.mp.microsoft\.com/

^([A-Za-z0-9.-]*\.)?au.windowsupdate\.com/

^([A-Za-z0-9.-]*\.)? download.windowsupdate\.com/


Reference:

https://docs.microsoft.com/en-us/windows/deployment/update/windows-update-troubleshooting

Print Friendly and PDF
Share/Bookmark

Allow Kaspersky Update pass-thru Sophos XG Firewall proxy (SFOS 17.1)

image

Add the exceptions policy, ^([A-Za-z0-9.-]*\.)?geo.kaspersky\.com/


Reference:

https://support.kaspersky.com/6105

Print Friendly and PDF
Share/Bookmark

Create firewall service for proxy only on Sophos XG Firewall (SFOS 17.1)

image

You need to Add TCP and UDP from ALL Source Port to Destination Port which is your proxy server for connect

Print Friendly and PDF
Share/Bookmark

Saturday, November 24, 2018

Sophos XG - SFOS 17.1.4 MR4 Released

If you are running on 17.1.3 MR3, please upgrade asap.


It fix many connectivity issues via proxy such as Windows 10 update failed, Kaspersky update failed…..


Since it just released, you need to download it manually.


https://community.sophos.com/products/xg-firewall/b/xg-blog/posts/sfos-17-1-4-mr4-released


Reference:

https://community.sophos.com/kb/en-us/132229 

https://community.sophos.com/kb/en-us/123285

Print Friendly and PDF
Share/Bookmark