Most engineers think…
Most people think a firewall's web filter is just a big block-list of bad sites, and that 'turn on YouTube blocking' is the whole job. That mental model falls apart the moment business video, HTTPS everywhere, and a saturated link enter the picture.
On Sophos Firewall, Web Protection, Application Control and Traffic Shaping are three linked controls attached to a firewall rule. You build web policies from allow/block/warn/quarantine rules keyed on category, identity and time; you control applications by category, risk and technology and let Synchronized App Control name the Unknown ones; and you use traffic shaping to guarantee and limit bandwidth. Crucially, on HTTPS none of the granular filtering works unless TLS inspection is on — without it the firewall only sees the domain. Knowing this split is what separates a real Sophos answer from 'I blocked the website.'
① Web filtering — categories, identity and time
Web Protection on Sophos Firewall is URL/web filtering driven by the SophosLabs URL categorisation database. You do not write one giant block-list; you build a web policy out of ordered rules, and each rule can allow, block, warn or quarantine traffic.
The power is in what a rule matches. A rule can match on web category (block Gambling, warn on Streaming Media), on identity — a specific user or group (Students vs Staff) — and on time via schedules (looser access after hours). Sophos ships default web policies you can clone and tune.
One rule does not enforce itself. A web policy is attached to a firewall rule: the firewall rule matches the traffic (zones, networks, users, services) and then says which web policy applies. The firewall rule is the decision point — remember that, because the same is true for app control and shaping later.
What is the role of a firewall rule for web filtering on Sophos Firewall?
② Activities, content controls — and the HTTPS catch
Beyond raw categories, a web policy controls activities and user activities — bundles that represent a behaviour, like 'streaming video' or 'uploading files'. You also layer on keyword and content lists, file-type blocking (stop executable downloads), SafeSearch enforcement (force safe search on Google, Bing and others), and YouTube restrictions (restricted mode).
Why HTTPS needs TLS inspection
Here is the catch every engineer must say out loud. Most of the web is HTTPS, and HTTPS is encrypted. Without TLS inspection (or legacy HTTPS decryption), the firewall only sees the domain (SNI) — not the full URL, the page content, keywords or file types.
That means your clever category, keyword and file-type rules are only partially effective on HTTPS sites until TLS inspection is enabled (with a sensible bypass list for banking and sensitive apps). Domain-level blocking still works; granular control does not.
Ordered allow/block/warn/quarantine rules using SophosLabs categories, matched by category, identity (user/group) and time, attached to a firewall rule.
Decrypts HTTPS so the firewall sees the full URL and content. Without it you only get the domain (SNI), so granular web rules barely apply.
Managed Sophos endpoints report the process behind traffic, letting the firewall name 'Unknown' apps it could not classify alone. Part of Synchronized Security.
A bandwidth policy with a guarantee and a limit, applied to rules, categories, apps or users — guarantee business apps, throttle recreational traffic.
In an interview, never claim 'I block sites by URL' without adding the caveat: on HTTPS that only works with TLS inspection. Without it the firewall sees the domain (SNI) only, so URL, keyword and file-type rules are partial. Mention a bypass list for banking and sensitive apps to show real-world judgement.
TLS inspection is OFF. A user visits an HTTPS site you wanted to filter by URL and file type. What happens?
③ Application control — and naming the Unknown apps
Application Control answers a different question: not 'which website', but 'which application'. Application filters identify thousands of apps and let you select them by category (e.g. File Transfer, P2P), risk level and technology, then block, allow or shape them. This catches apps that ride over ordinary web ports and would slip past a pure URL filter.
The problem: some traffic is genuinely Unknown — the firewall's signatures cannot tell what app produced it. That is where Synchronized App Control comes in. As part of Synchronized Security, managed Sophos endpoints report the process behind the traffic, so the firewall can name the Unknown apps and you can then add them to an app filter to block or shape.
The interview line: app control sees apps the web filter cannot, and the endpoint sees apps the firewall cannot. Together they remove the 'Unknown' blind spot.
A web policy filters by website category; application control filters by the actual app (by category, risk and technology) and can catch apps tunnelling over web ports. And for traffic the firewall can't classify, only Synchronized App Control — using endpoint data — can name the Unknown app. Treating them as the same tool loses you marks and blind spots.
▶ Watch one user's video + SaaS traffic get classified and shaped
How a single user's mixed traffic is filtered and shaped end-to-end. Press Play for the healthy path, then Break it to see the classic HTTPS failure.
The firewall logs a chunk of traffic as 'Unknown' application. What is the Sophos way to identify it?
④ Traffic shaping — protect business bandwidth
Blocking is blunt. Often the right answer is not 'block recreational video' (which breaks legitimate video) but 'don't let it starve the business'. That is traffic shaping (QoS). You create a bandwidth policy with a guarantee and a limit, then apply it to firewall rules, web categories, applications or users.
Prioritise, then throttle
The pattern: guarantee bandwidth for business apps (ERP, Microsoft 365, voice) so they never slow down, and limit recreational categories and apps (Streaming Media, OTT, social) so they cannot saturate the WAN. Because shaping attaches to the same firewall rule, you can shape exactly the traffic a rule already matches.
Common pitfalls to avoid: blocking a whole category that breaks a needed SaaS — fix it with an exception rather than a wider block; recreational video saturating the link — fix with shaping, not a ban; and HTTPS sites only partly filtered — turn on TLS inspection so category, keyword and shaping rules actually apply.
Priya at a Kochi EdTech firm faces this
During school hours the internet crawls — the ERP and Google Workspace are slow and video lessons buffer, even though the link size should be fine.
Recreational video (YouTube, OTT) is saturating the WAN; no traffic shaping reserves bandwidth for business apps, and a blanket category block was avoided because it would break legitimate educational video.
In Reports the Streaming Media category is the top bandwidth consumer; the firewall rule carrying student traffic has no traffic-shaping policy and applies one web policy to everyone.
Sophos Firewall ▸ Reports ▸ Applications & web / Bandwidth, then Rules and policies ▸ the relevant firewall ruleCreate a bandwidth (traffic-shaping) policy that limits Streaming Media / OTT apps and guarantees the ERP and Workspace apps; attach shaping to the firewall rule; make the web policy identity-aware so staff get more latitude than students; ensure TLS inspection is on so HTTPS streaming is actually classified and shaped.
Re-run the bandwidth report — Streaming Media drops to its cap, ERP and Workspace latency falls, and live educational video still works because it was guaranteed, not blocked.
Never close a 'net is slow' ticket on a hunch. The Sophos bandwidth and application reports show exactly which category, app and user is consuming the link. Read that first, then shape the real culprit — don't guess and block.
Recreational video is saturating the WAN, but staff also run legitimate video lessons. Best Sophos fix?
🤖 Ask the AI Tutor
Tap any question — instant, scoped to this lesson. No login, no waiting.
Pre-curated from vendor docs + community Q&A, scoped to this lesson. For a live prod issue, paste your export into chat.techclick.in.
📝 Wrap-up assessment — six more
You've answered 4 inline. Six left. 70% (7 of 10) marks the lesson complete on your profile. Tap Submit all answers at the end.
🧠 In your own words
Type one line: why is 'I blocked the website' an incomplete answer for HTTPS filtering on Sophos Firewall? Then compare with the expert version.
🗣 Teach a friend
Best way to lock it in — explain it in one line to a teammate. Tap to generate a paste-ready summary.
📖 Glossary
- SophosLabs URL categorisation database
- Cloud-maintained classification of websites into categories (e.g. Streaming Media, Social Networking) that web rules match against.
- Web policy
- An ordered set of rules on Sophos Firewall that allow, block, warn or quarantine web traffic by category, identity and time.
- Web category
- A group of similar sites used as a match criterion in a web rule.
- TLS inspection
- Decryption of HTTPS at the firewall so it can read the full URL and content for granular web rules; without it only the domain (SNI) is visible.
- Activities / user activities
- Bundles of categories and file types representing a behaviour (e.g. streaming video, uploading files) controlled within a web policy.
- Application Control
- Identification and control of applications via app filters by category, risk and technology — block, allow or shape.
- Synchronized App Control
- Use of managed Sophos endpoint data to identify and name 'Unknown' applications; part of Synchronized Security.
- Traffic shaping / QoS
- Bandwidth policies with a guarantee and a limit applied to rules, categories, apps or users to prioritise or throttle traffic.
- Firewall rule
- The match-and-act unit that decides which web, application-control and traffic-shaping policy applies to traffic.
📚 Sources
- Sophos — Sophos Firewall: Web protection, web policies and SophosLabs categories. docs.sophos.com
- Sophos — Sophos Firewall: TLS inspection / HTTPS decryption for web filtering. docs.sophos.com
- Sophos — Sophos Firewall: Application control and application filters. docs.sophos.com
- Sophos — Synchronized Security and Synchronized App Control (naming Unknown apps). docs.sophos.com
- Sophos — Sophos Firewall: Traffic shaping (QoS) and bandwidth policies. docs.sophos.com
- Sophos — Sophos Firewall product page and datasheet. sophos.com
What's next?
You can now control users browsing out. Next, flip it around: the Web Application Firewall (WAF) — Sophos Firewall's reverse-proxy mode that protects the servers you publish to the internet, not the users behind the firewall.