r/sophos • u/Bubbly-Long5326 • 5h ago
Question Can't log in to sophos
anybody else experiencing this issue at the moment?
r/sophos • u/Bubbly-Long5326 • 5h ago
anybody else experiencing this issue at the moment?
r/sophos • u/Unable-Compote2695 • 5h ago
Hi Sophos team, our non-profit site [https://www.mobileloavestc.org/](https://www.mobileloavestc.org/) is flagged as Spyware/Malware. Intelix Machine Learning rates it 'Likely Clean', but non-customers can't click 'Disagree' or post on the Sophos Forum due to account approval locks. Could a moderator please submit a URL reassessment on our behalf?
r/sophos • u/BusResident8841 • 9h ago
Hi Sophos Team,
Could someone please help submit a URL reclassification request on my behalf for https://unitedsportsqatar.com?
I have already cleaned the website by removing the malicious files, and the latest Intelix analysis shows the page content as Likely Clean. However, I'm unable to use the Disagree? option because I'm not a Sophos customer and my account isn't eligible for support.
r/sophos • u/Suspicious-Secret338 • 13h ago
Hi,
can you assign a user as the “owner” of a shared mailbox in Sophos Central Email Protection, similar to how it works for distribution groups?
I’d like a user to have access to the quarantine in the Self Service Portal for a shared mailbox, not just be able to release messages via the quarantine report.
thank you
r/sophos • u/Whale-fucker69 • 1d ago
When my work disbanded I was allowed to keep my computer, but when I brought it home Sophos was still installed on it. This wouldn’t have been a problem until I tried to connect the computer to Ethernet and it couldn’t find a gateway. After a lot of effort finding the issue I realised the problem was something to do with sophos. I promptly uninstalled sophos using the control panel which allowed me to connect to the internet. I then reset the computer and I was unable to connect again. How do I fix this? Has anyone else encountered this?
r/sophos • u/OkRoutine9636 • 1d ago
So we have this voip calling cloud platform and when users try to call via the platform it returns 406 error. i did everything i can disabled sip and h.323 protocol and disabled udp ddos and increased udp timeout and udp tiemojut stream still the issue presists. and disabled the alg on router for sip and h.323 too. still the issue persists and tried disabling ssl/tls inspection for the site but no help?
r/sophos • u/Potential_Future1052 • 2d ago
Hi All - I have a question about the architecture of DNS protection setup. The article (Configure Sophos Firewall to use DNS Protection - Sophos Central Admin) directs you to configure all endpoint devices to point to the firewall for DNS and add a DNS request route to your local server for local DNS resolution.
My question is, can we rather leave the devices pointed to the local server and update its forwarders to use the DNS protection IPs. Will this accomplish the same thing or am I missing some level of protection in this configuration?
Thanks
r/sophos • u/elliottmarter • 2d ago
We use Datto RMM and the component which silently installs Sophos endpoint has stopped working.
when I check the logs it's failing to download the .exe if I grab just the powershell invoke web request and run that on its own it also fails to grab an exe.
when I visit the URL manually I get an empty site with a 400 response.
I logged this with Datto but they closed it and said it's a sophos issue.
any ideas?
Hi everyone,
I’m planning a new hardware build for Sophos Firewall Home and I’m a bit unsure about storage support in v22.
From what I’ve read, starting with Sophos Firewall v22 the new kernel supports UEFI boot, so we no longer need legacy BIOS. Does this also mean that NVMe drives are now properly detected and supported as system disks in the Home Edition, or is it still safer / required to use a SATA3 SSD?
My planned setup is:
r/sophos • u/Ragnor_lothbrok • 5d ago
Hi , We have a Sophos XGS 6500 deployed in Location A and a Sophos XGS 4500 in Location B. Since these sites are geographically distant, we are planning to establish a secure tunnel between the two appliances.
For a permanent, high‑throughput link between two full XGS appliances (not lightweight branch offices), we would like to know which technology Sophos recommends: Firewall RED (Server–Client) or Site‑to‑Site IPsec, and the reasons behind this recommendation.
Additionally, we request a detailed comparison covering the following points:
Thanks in advance!!
r/sophos • u/rau-systemberatung • 6d ago
Make admin work great again!
We found that even just looking for logs from 1 hour ago could be a bigger challenge than it had to be, and from the way the XGS stores its logs in SQLite databases, there's also no log file that can be downloaded via SSH. Of course there's Sophos Central log access but we found filtering can be somewhat flaky and its fixed 50-entry-pages, or setting up a syslog server.
The extension is completely free and all data stays locally in your browser; we use it for our own admin work every day and thought it might be useful. Please note that the way the XGS exposes logs it can take a while for them to propagate in the GUI.
r/sophos • u/Lucar_Toni • 6d ago
We released the Import/Export API for Sophos Central Partner / Customers:
Used the time to explain, how it works and how it can be potentially be implemented to own workflows.
Keep in mind: This is an API, means, it is open for all kinds of customization.
r/sophos • u/Content_Ad1015 • 6d ago
Recently I found out that my website (https://qcrepository.org) is categorized as phising/malicous by a few vendors including Sophos. My question is, where do I submit a false positive report? I tried the link mentioned in similar posts (https://support.sophos.com/support/s/filesubmission?language=en_US) but after submitting my website, it just gives me a false report saying that it's phishing without an option to report for review.
Thanks!
r/sophos • u/Specialist_Editor245 • 6d ago
Hi,
I have a question regarding the Directory Services (Active Directory Sync) feature in Sophos Central.
Does the AD Sync have any direct benefit or relationship with Sophos Endpoint / Intercept X, or is it only used for synchronizing users and groups from Active Directory?
Additionally, are there any important considerations or best practices I should be aware of before installing and configuring the Directory Services synchronization on the Active Directory server? For example, does it have any impact on existing Endpoint or Intercept X deployments, or are there any specific permissions, prerequisites, or potential risks that should be considered?
r/sophos • u/bengillam • 7d ago
Anyone else have this issue,
2 wan connections 1 Sogea/1 4g
troubleshooting wan connection which says its connected.
If you tell it to traceroute or ping via WWAN1 it just falls back to the landline connection.
The only way to get a true result is to do it in CLI.
Seems to make the gui tools pretty useless for intended purpose this is on an xgs 136 on 22.0.2 and was same on 22.0.1
Which is all the more frustrating as the documentation for the CLI leaves a lot to be desired gives a list of parameters but no indication of the syntax of a valid command
r/sophos • u/Lucar_Toni • 8d ago
All sounds promising but also looks like more additional skus and how many do you have to purchase.
Considering our Sophos Intercept X XDR is up for renewal next year and we're thinking about moving to Defender P2, it'll be interesting for us
r/sophos • u/Money-Move-1152 • 8d ago
I have intercept x on my phone, it works really well, but my problem is that sometimes the anti virus data gets outdated, but everytime I press it, it doesn't update, it says it does, but it doesn't, the same error stays on screen. I have it scan stuff while charging but I don't know what is happening
r/sophos • u/Forumrider4life • 8d ago
about 5 years ago Sophos moved from a free home edition to free trial. They posted that all existing users would keep up to 3 licenses for Sophos home free after they made the change, however after a reinstall on the same machine today, that does not seem to be the* case, the same account ive had for years now shows my machine greyed out, seems once you remove it those 3 licenses vanish and leave you with nothing... so much for Sophos :)
r/sophos • u/YellowOnline • 9d ago
r/sophos • u/Lucar_Toni • 9d ago
r/sophos • u/Eliminateur • 9d ago
Hello,
i'm pretty sure after MR1 update one sd-wan route stopped working (and i cant find any tools on the firewall itself to diagnose this, as there's no route simulator):
background: SFOS 22MR1 VM with 2 WAN links
Rule setup:
Incoming int: LAN
Source network: LAN network
Destination: any, any app, any user
Services: SMTP and SMTPS
Link selection: Only WAN2 gateway, no backup, only route specified
Both wans are active, and are set as active-active in wan link manager.
Firewall rules allow the traffic.
But if i try to connect to the servers i need it fails(as wan 1 ISP blocks those ports) or if i traceroute, it goes through WAN1!.
In fact i just changed the rule so that ALL traffic to the destination server defined as FQDN goes through WAN2, and it's still failing.
Edit2: I disabled WAN1 on network connections and the connection to that remote host started working, so the sd-wan in effect is broken
Edit3: After re-enabling WAN1 it seems that the system fixed itself and now the route is working
what's going on?
r/sophos • u/titiano2000 • 13d ago
Tengo que modificar el cluster ID de un sophos xgs 3100 configurados en HA y en modo activo-pasivo
La duda que tengo es que si es necesario deshacer el HA y volver a rehacerlo con el cluster ID ya cambiado o si directamente modificando el apartado de cluster ID en el primario ya valdría?
r/sophos • u/rankostamatovic • 13d ago
I'm trying to resolve what appears to be a false positive from Sophos.
Here's the situation:
.htaccess with a minimal configuration and verified that HTTPS is correctly enforced.My problem is that I cannot find any way to contact SophosLabs for a manual review.
I tried creating a Sophos account, but my registration keeps getting rejected, so I cannot submit a false positive request through their portal.
Has anyone successfully had a domain reputation corrected by Sophos?
Any advice would be greatly appreciated.
r/sophos • u/Will_Sophos_Engineer • 14d ago
Everyone remembers WannaCry. WantToCry sounds like the same thing. It isn't. It encrypts your files remotely over SMB using nothing but stolen credentials and right now 1.5 million devices are sitting exposed on the public internet.
In this episode we break down how remote ransomware works, why your antivirus and EDR never see it coming and what caught it in our Sophos telemetry