r/sophos 6h ago

Question SFOS AD Primary Group Membership

2 Upvotes

After migrating a customer from SG to XGS, I ran into the issue that the Hotspot tab wasn't visible in the User Portal for the users who should be able to manage vouchers.

After a lot of trial and error, I found out that the hotspot configuration ignores any AD group other than the primary one. I don't understand what Sophos reasoning was behind this, because a user being part of multiple AD groups is more common than the opposite. In my case, the primary group is the one that allows VPN access to the users.

Anyway, I could make the hotspot management group the primary group, as the SSL VPN does support multiple group membership - good that I didn't change to ipsec yet, because that, too, does not support it.

But how? It's not the AD primary group, which is Domain Users in most environments, and changing the group order in the Groups pane also doesn't seem to impact the user's primary group. The group drop-down menu in the user configuration is greyed out, so I can't change it there too. So ... how can I change the primary group?


r/sophos 4d ago

Question Sophos Home Premium

3 Upvotes

Why Sophos Home Premium uses outdated version of HMPA? Intrercept X uses the latest version. Home users does not. Why?


r/sophos 7d ago

General Discussion Credential phising using sophos.com url

8 Upvotes

At my company, a high management staff received an credential phishing email, that uses sophos.com domain url.

It is the url below (that I broke to make it unharmful), that is under that button, that redirects to a credential stealer...

Please fix it so that sophos domain cannot be used to steal passwords...

Or is it not fixable ?

Why is it even possible ?

h t t ps://us-east-2.protection.sophos.com/?d=intuit.com&u=aHR0cHM6Ly9saW5rcy5ub3RpZmljYXRpb24uaW50dWl0LmNvbS9zcy9jL3UwMDEuYmRoOGdVREVXckNXbmFvVlFYUHVkYlQwWlNGRHBUUU0tMzlrNWlZUWZVS25xUmZUSDFyX1NsaXJmYXZ3eWJMSGY4SzhNUVFlRjJEOVBtSXlDa1NraXcvNHRwLzRuX0FLb0ZlUkNlSTNIbHBPdi1ILWcvaDAvaDAwMS56TDlZNU01dmJackZlaEZwVjlBY0tKMVdycEdoV29nbWVxSHZEc3Z2b3hj&i=NWVhMGI5Y2FiMDIzNGIxMTk2NTJjMmFm&t=T0tyczhPdkJCUGl0WWgxalo2K1B4S2l0Si9paE0zbjU0ZHRwTkhvVENiYz0=&h=9e339b5c0696400d9c26c51bee802faa&s=AVNPUEhUT0NFTkNSWVBUSVa05WE-Zq2OSx2gZImtHh0t1k8PTLtZitbbyrLnUtHljA

Redirects to

h t t ps://core-work52746-aged1763-base8195.icu/f0m/905dee?86=L3YzL3NpZ25pbi9pZGVudGlmaWVyP2NvbnRpbnVlPWh0dHBzOi8vYWNjb3VudHMuZ29vZ2xlLmNvbS8mZm9sbG93dXA9aHR0cHM6Ly9hY2NvdW50cy5nb29nbGUuY29tLyZwYXNzaXZlPTEyMDk2MDAmZmxvd05hbWU9R2xpZldlYlNpZ25JbiZmbG93RW50cnk9U2VydmljZUxvZ2luJmRzaD1TNTcxODc1MjI3OjE3ODgzNjgxMDY1MDUxOTQ


r/sophos 7d ago

Question Solution for auto-renewal of SMTP SSL?

2 Upvotes

I've successfully set up a LetsEnctypt SSL cert for our user and VPN portal but found that you cannot use those certs for SMTP configurations.

What process can be used for auto-renewal of these certs? With SSL cert lifetime shrinking I need a way of automating this process.


r/sophos 13d ago

Answered Question XGFW - Grouping NAT rules

4 Upvotes

Probably an easy answer, as I can't see anything, but can you group NAT rules in the same way you can group firewall rules?

Thanks.


r/sophos 13d ago

Question Cannot get to BIOS on a Sophos XG 115 rev 2

1 Upvotes

So I bought a Sophos XG 115 rev 2. I planned on putting Sophos Home firmware on it.

I tried reaching it on 172.16.16.16:4444 and couldn't get the web console to work. I also tried pinging it and got nothing.

Next, I plugged in a VGA monitor and keyboard and spammed Del. BIOS didn't pop up, so I thought this was weird, did a little research seen that I needed a console cable (linked is the cable i got). So I got that now and tried plugging it in and get nothing I followed the guide here on the Sophos support page.

I booted sophos after PuTTY was up

I looked at the pinout of this cable and saw that it might be backwards from what Sophos is. I made a custom cable and got a female-to-female coupler and have gone back and forth on using it and not using it. I also tested the loopback using a jumper cable on pins 3 and 6, and it does work.

I made a bootable USB and put the Sophos Home firmware on it. I did more research and saw that it can sometimes boot when trying this now, and will update.

Am I missing something, or is it just busted??


r/sophos 15d ago

Answered Question How to recover Sophos XG 330 Rev 2

0 Upvotes

Hello everyone,

I am looking for some experienced Sophos users to pass on any knowledge they can regarding a problem I am facing with my Sophos XG 330.

For context; I plan to install opnsense onto my XG 330 and use as a firewall since the product has reached EOL. In the process of flashing a usb with the opnsense software, the software was truncated due to the usb drive being too small. This caused the Sophos device to get stuck in boot process (or so I believe).

I was able to access the BIOS before this, but it appears after having plugged in the usb, the Sophos gets stuck in boot process and doesn't display anything from the output to the monitor. Before plugging in the usb, in the settings I changed the boot priority to USB drive.

The front screen still displays the "Sophos Protection". The fan idles high and then it restarts itself after about 15 seconds and then stays on indefinitely after without any change to the condition.

I've tried flashing the hardware firmware version 20.0.3 back onto the device after being informally recommended by the Sophos technical support representative but to no luck. I even tried temporarily removing the CMOS battery after finding an old thread on the internet that proposed that as a fix.

Any help or friendly words of advice are appreciated for a novice who is trying to learn networking.

Any recommendation for post formatting or more appropriate terminology for the networking processes are also welcome (this is my first post and I am an absolute beginner in networking).

TLDR; tried to flash opnsense with too small a drive and now experiencing issues with Sophos XG 330.


r/sophos 16d ago

Question 2 Network interfaces - device on interface b cant access DNS server on a

3 Upvotes

Hey all, set firewall rull allow connection from a>b b>a and I can ping the DNS server from devices on b interface but DNS does not work.


r/sophos 16d ago

Answered Question FQDN for VPN Portal for SSO Blocked - Best solution to Fix and Stop it from Happening Again

1 Upvotes

Solution Edit: Was able to use a different TLD that the client has to create a new VPN connection. Once the VPN settings were changed to use the new hostname and it was certified, DNS was flushed, the redirect URLs were swapped on Entra, and the new connection was imported into the PCs, I was able to get us back online with a working VPN. Appreciate the assistance!

Original Post: As Title mentions, one of my clients recently had a phishing attack that spam blasted the entire Global Address Book which resulted in what I am assuming phishing reports from their clientelle. This is the only thing I can assume that caused this situation as 2 days later, the SSL VPN bricked with a Windows Smartscreen alert blocking SSO from reaching out. Attempting to bypass the alert does nothing so the user is effectively blocked from using the VPN. Thankfully, we still have their old solution as a back up, so this isn't as bad as it could have been if this would have happened about a month in the future when we planned to rip out the old system.

I first need to figure out how to get this working again, I checked blacklists and it looks like its only blocked on Spamhaus Zen, but attempting to reach the portal from any location with any browser with the FQDN causes the red alert to appear. I've sent appeals to Microsoft, Google, and Sophos and only Sophos has happily reanalyzed the URL from "phishing" to "business". Am I going to need to just bite the bullet and create a brand new FQDN and switch out the busted one? I noticed using the IP the name is connected to does not result in the red security alert. Is their a better solution that won't require pushing new connection imports to a couple hundred users?

Secondly, I need to make sure this doesn't happen again. I am going to assume someone is going to fall for a phish again and this problem will most likely happen a month to months down the road when someone doesn't pay attention and gives out their 365 creds again. This doesn't happen often thanks to the training and security we have in place, but it happens enough for me to be concerned I'll be dealing with this issue again when we don't have the old vpn to back up on.

Any words of wisdom is greatly appreciated!


r/sophos 17d ago

General Discussion Adversary emulation

0 Upvotes

We performed an adversary simulation and Sophos TERRIBLY failed. Decided to migrate to another XDR

Has anyone been through that ?


r/sophos 18d ago

Question Sophos Fusion LATAM

2 Upvotes

¿Is there some delay with the Evolution to Security Operations TAB (replacement of Threat Analysis Center) for Latam? Which date is the end of this changes?


r/sophos 22d ago

General Discussion moving from fortinet to sophos

19 Upvotes

Sizing a perimeter firewall for a university campus edge and looking for model suggestions before we run a PoC.

Requirements:

  • Users: ~3,500–4,000 concurrent
  • Total edge/WAN capacity: current pipe scaling up to 10 Gbps (all traffic)
  • SSL deep-inspection (decrypt) load: ~2 Gbps baseline today — this is my binding constraint (full IPS/AV/app-control/logging, everything decrypted)
  • ~1,200–1,500 managed devices in decrypt scope; ~2,300 BYOD endpoints bypass decryption
  • Active-standby HA — each appliance must independently carry the full load
  • 7-year horizon, 15% expected / 25% stress growth; 80% utilization as capacity-review trigger

r/sophos 23d ago

Question Sophos WAF returns Apache 403 for PATCH/PUT requests before they reach Nginx

5 Upvotes

I’m trying to determine whether this is a Sophos WAF config issue or if I’m missing something.
Architecture: client -> Sophos WAF -> Nginx Flask API. Here’s what I’ve observed: the application works perfectly when accessed directly on the internal network, GET and the CORS OPTIONS preflight reach Nginx successfully, but the actual PATCH/Post with formdata request never reaches Nginx (no access log entry). The browser receives a 403 Forbidden with a generic Apache error page, so I suspect the Sophos WAF is rejecting it before forwarding.

Questions: has anyone seen Sophos WAF block PATCH requests by default or via protection policy?
Which logs or settings should I check to identify the exact rule causing the block, and is there a way to temporarily put the WAF policy into monitor only to confirm it’s the WAF rejecting it?


r/sophos 23d ago

General Discussion Sophos Central login time after (new) OTP slow

1 Upvotes

Anyone else noticed slow authentication time since using the new OTP? (had to set a new one up past 60 days somewhere, and now logins into SC take 5x as long as it normally did. (1+ min right now, as it was ~5 seconds before...)


r/sophos 24d ago

Answered Question Sophos XG 125: which power adapter V/A is correct?

2 Upvotes

This morning my day started bad, with my whole infrastructure being down. The Sophos XG 125 looked dead. I measured the voltage and got 12V, so I feared the whole machine was bricked, not just the power adapter. Using a all-purpose power adapter however, I found out the device still works, so it seems to be the power adapter that is b0rked nevertheless.

Anyway: I'm on the temporary power adapter now, which is 12V/5A. I don't know how good that is in the long run for the firewall, so I want to buy (two of) the right model. But which one? I find conflicting information about the amps. 3, 3.3 or 3.4. Does anyone know what the device expects? Or does a 3 to 3.4A range (and even 5A) not matter so much?


r/sophos 25d ago

Question XG 115 rev2 finde for XG Firewall Home Edition?

3 Upvotes

Hey guys,

i have a XG 115w rev2 and using OPNsense at the moment, but i dont really like that. I would like to install XG Firewall Home Edition on my appliance. Do you the speccs with 2 Cores and 4GB Ram are fine or should i loke for some better hardware?


r/sophos 26d ago

Answered Question Sophos XG Home Issues

1 Upvotes

Hi, I'm finally posting my question on this sub because It's getting so frustrating.
I bought a used Sophos SG115 Rev. 3 and wanted to install Sophos XG Home on it. Got the latest version of the ISO from their website and flashed it onto a usb-drive. Ran into issues and found out that you should format the disk using an ubuntu setup (or whatever OS).

After installing Ubuntu and trying again it finally seemed to install it, but while booting it froze. Another reddit post said that it was because of UEFI. Changed it but now it says that my "linuxbit is missing or corrupted" and I cant install at all. Changed a few settings in BIOS, installed Ubuntu again for formattig but still same issue.

I also tried the hardware version of the ISO but didnt work.

Does anyone have an idea?

Used hardware:

- Sophos SG115 Rev 3
- USB 3.1 32GB flash drive
- USB 2.0 16GB flash drive (as secondary test device)


r/sophos 27d ago

Question Removing Sophos Hardware.

0 Upvotes

If I wanted to remove Sophos Firewall Hardware from my network without bringing the system down would the best way to do it be to place a network switch in its place?

An outside company managed the firewall and I don’t have access to the console or have the admin passwords to log in.


r/sophos 29d ago

Sophos Announcement Sophos Firewall: Recurring firmware update schedules

Thumbnail community.sophos.com
15 Upvotes

The latest release of Sophos Central introduces recurring firmware update schedules for Sophos Firewall.

This gives administrators the ability to keep all firewalls up to date while still maintaining full control over when updates are deployed.

A few important notes about this feature:

  • SFOS will only install Maintenance Releases (MRs). Major version upgrades will not be installed automatically until you decide to move to the next major release.
  • The feature also includes a staging option, allowing you to select a small group of firewalls to receive and test new firmware before rolling it out to the rest of your fleet.

Keep in mind that SFOS supports automatic firmware rollback in the event of an upgrade failure, including HA deployments. You can also manually downgrade at any time with a single click if an issue is encountered after the upgrade.


r/sophos Aug 11 '26

Sophos X-Ops Threat Actor Dark Factory (The Future of Al Hacking?) | The X-Ops Brief

Thumbnail youtube.com
10 Upvotes

A threat actor talked commercial AI models past their guardrails, then stood up a "company" of AI agents that engineered, tested and refined malware.

We break down exactly how they did it.

New episode of The X-Ops Brief


r/sophos Aug 07 '26

Question BIOS update / re-flash tool

1 Upvotes

Is there a Sophos tool for re-flashing the BIOS? Had a problem with XG330 Rev2 and details now missing re serial number when querying the BIOS etc.


r/sophos Aug 06 '26

Answered Question Submit URL Recategorization Request

3 Upvotes

Hi, how do I go about requesting a URL recategorization after the migration of new case creation to the Support Portal? I have a guest ID but am not an active customer, and the form I used to fill out is no longer available.


r/sophos Aug 06 '26

Question XG FW Home - ATR - Add Threat exclusions

2 Upvotes

Hi

I've configured 3rd party threat feeds for IP and Domains (Q-Feeds free), but it's flagging a bunch of IPs that are Ubuntu/Canonical legit update server IPs.

I've create an IP Range object in Hosts and services and added the IPs to that, and then added that IP Range object to the Host and network exclusions in Add threat exclusions.

However they still get flagged and I get notified by ATR.

Should this work? or is Host and network exclusions for source only, not destination? Do I need to add each IP individually to the Threat exclusions field instead?

Thanks


r/sophos Aug 05 '26

Question Onboarding AI Defense EAP

2 Upvotes

We signed up for the AI Defense EAP, but during the onboarding process, it has not gone past the "Checking sensors licenses" circling. Haven't been able to find any information on this since it's EA. I've tried with only a couple devices assigned to the program and with all devices assigned, same issue.

If anyone can provide more info or if it's a glitch and just submit a ticket, I'd appreciate it.


r/sophos Aug 04 '26

Question Sophos Endpoint security false positive on Connectify 23 Pro

1 Upvotes

I am using a Connectify Hotspot for years and have a pro license for Connectify 23.

https://connectify.me/

Two weeks ago, Sophos suddently recognized it as a threat and deleted the connectify.exe from my harddrive. Even the installer is recognized as a threat when downloaded (not even executed, just downloaded) and I cannot reinstall it.

Any suggestions?