T Techclick ← Sophos hub
Sophos · Central + XGS · Session factory · Interactive lesson

Sophos is a Central + XGS factory. Device, intercept, then the log.

The ticket says “Sophos isn’t working.” Finance cannot open Outlook Web. Someone already stacked a second Accept on the XGS. Someone else sent a phone photo of a green Intercept X shield. Neither is a factory ticket. Sophos manufactures a path: device / policy in Central, Intercept X on the laptop, then an XGS firewall rule / SD-WAN / VPN, and the product that leaves the line is the log. This lesson is that order, the official field names, and the proof that closes the ticket.

20 min read · L2 primary · Quiz at end · Dummy values only

⚡ Quick Answer

Sophos is a Central + XGS policy factory: device/policy → Intercept X → firewall rule / SD-WAN / VPN → log. Prove assignment, heartbeat, then Log viewer.

After this page you can

Quick answer

Sophos is a Central + XGS policy factory. Central assigns a device a policy and Intercept X intercepts on that laptop. The XGS then stamps the same conversation with a firewall rule, an SD-WAN path, or a VPN tunnel. Success is a Log viewer row with log_type and fw_rule_id — or an official SD-WAN / IPsec status field when the WAN died before a Destroy could be logged. A Base Policy existing in the list is not assignment. A green shield is not Health status. Accept is not the log.

Say this out loud

I do not start with another Accept. I name the laptop in Computers & Servers, quote the Policies tab, then ask whether Intercept X is sending a heartbeat to this XGS. Only then do I read the firewall rule, the SD-WAN gateway, or the IPsec Connection. I close with a log field, not a screenshot of a shield.

Concept

Two floors, one ticket. Central prints identity and Intercept X. XGS prints the network stamp. The log is the finished product.

Path

Device/policy → Intercept X / Security Heartbeat → firewall rule or SD-WAN or VPN → Log viewer (log_type + fw_rule_id).

Do

Side A assigns and proves the Central policy. Side B stamps the XGS rule / path. Side C quotes the log. Do not invent a second Accept.

Desk

Night-shift “is it working?” is five proof tools. That write-up lives on the evidence desk. This page is the factory that desk inspects.

1. Why a green shield is not a session

Every other blog starts with “turn on Intercept X” or “add an HTTPS Accept.” That is why juniors freeze at 01:40. The real object is the policy path. Features are stamps the factory puts on one conversation before it lets two sides talk — and before it writes a log line you can paste.

Official Central: you manage protected computers on My Environment → Computers & Servers. Health is an icon beside the name (Good / Warning / Bad / Unknown). Last active is Online or a last-contact timestamp. Agent mode is Endpoint, XDR, or XDR Sensor. The policy that actually applies is on that computer’s Policies tab — not the fact that a Base Policy exists in My Products → Endpoint → Policies.

Official XGS: firewall rules control how traffic flows between zones. Sophos Firewall evaluates rules, not rule groups, top-down, first match. After Accept it can still apply a linked NAT, a web policy, Synchronized Security Heartbeat, an SD-WAN route, or an IPsec selector. The session is logged when the firewall receives a connection Destroy — not when you click Save.

Hero · two floors, one ticket
Teaches: a laptop request walks Central policy, Intercept X, then XGS rule / path stations before a log is printed
Notice: the product is not “Sophos allowed it.” The product is a stamped path you can quote in a log.
The lie every L1 repeats

“The shield is green and the rule is Accept, so Sophos is fine — add a wider rule.” A green tray icon is not the Computers & Servers Health status column. An Accept only means the XGS was willing to print the network stamp. If Intercept X was never assigned, or Heartbeat is missing, or Destroy never arrived, widening the rule just prints more dead tickets.

What the ticket asked

“Sophos is blocking Outlook.” That sentence is a hypothesis. The factory may have no device, a wrong policy, a red heartbeat, or an Accept with no log.

What you prove first

Identity of the laptop, then the assigned policy, then heartbeat to this XGS, then the live rule or path, then one log field. The evidence desk is the night-shift version of this order.

2. Mental model — four stamps, two floors

Hold four stamps. Interviews fail when people mix the Central floor with the XGS floor.

1. Device / policy Central

Is this computer in the estate, online, and assigned the Threat Protection (and any Web / Peripheral) policy you intended? User policy vs device policy + list order decide what wins.

2. Intercept Intercept X

Intercept X is the agent that enforces that policy on the laptop. Security Heartbeat is how the endpoint tells a registered XGS its health (green / yellow / red / missing).

3. Path stamp XGS

Firewall rule (Accept / Drop / Reject + Log firewall traffic). Then SD-WAN if you steer ISPs. Then IPsec / SSL VPN if the site path is a tunnel. These are three stamps, not three products.

4. The log Proof

Log viewer (upper-right of any XGS page) is the finished ticket: module + log_type + fw_rule_id. Central Events / TAC Detections are the endpoint floor’s log. Empty is allowed to mean “logging off” or “no Destroy yet.”

Flow 1 · four stamps on one conversation
One conversation. Two floors. Four stamps. 1 Device / policy Computers & Servers Health · Last active Policies tab assigned TP-Finance-Intercept Central floor 2 Intercept Intercept X agent Heartbeat to XGS green / yellow / red min HB = Yellow Still Central + XGS 3 XGS path Firewall rule 14 or SD-WAN SLA or IPsec Connection Accept + Log traffic XGS floor 4 Log Log viewer module Firewall Destroy arrives fw_rule_id=14 Finished ticket Pre-train these words before you touch a runbook Base Policy — default catch-all. Existence in the list is not “this laptop has it.” Open the Policies tab. Security Heartbeat — endpoint health sent to each XGS registered with the same Central account. Accept / Drop / Reject — firewall action. Accept is permission, not a two-way session and not a log line. Destroy — Log viewer writes the firewall session when the connection closes with a Destroy. WAN death can leave the log empty.

Read left → right. If you cannot name the stamp, you will open the wrong console. Central first, then XGS, then the log.

Device / policy answers “is this laptop even in the factory, and which recipe did Central hand it?” Official: a user policy applies to every device that user signs into. A device (computer) policy applies to specific computers or groups, regardless of who logs on. If both could apply, the policy higher in the list wins. You check by opening the computer → Policies. Source: About Policies + Computer Policies.

Intercept answers “is the agent enforcing that recipe and telling the firewall it is healthy?” Official Threat Protection: a device’s health is red if it has threats, out-of-date software, is not compliant with policy, or is not properly protected. Device Isolation can isolate red devices. Security Heartbeat on the XGS firewall rule sets Minimum source HB permitted (Green / Yellow / No restriction) and optionally Block clients with no heartbeat.

XGS path answers “which door, which ISP, which tunnel?” Firewall rules match source zone, destination zone, networks, services, optional users, then action. From SFOS 18 onward, routing lives in SD-WAN policy routing, not inside the firewall rule. Site-to-site IPsec is policy-based (selectors + a matching firewall rule) or route-based (XFRM + static / SD-WAN routes).

Log answers “which module wrote the last word?” Official Log viewer: firewall sessions log on Destroy. SSL/TLS logs after the handshake completes and when the connection closes. Syslog field names you quote: log_type, log_component, fw_rule_id.

3. Factory path — device → intercept → XGS → log

Flowchart first. Prose second. This is the whiteboard when someone says “internet is down” or “Sophos blocked Outlook.”

Path · assigned vs intercept vs XGS
Teaches: a decision diamond splits a healthy assigned device from a missing intercept or a dead XGS path
Notice: the diamond is not allow/deny. It is “which floor failed — Central assignment, Intercept heartbeat, or the XGS path?”
Flow 2 · official order (student labels)
Laptop click → Central floor → XGS floor → log Outlook click In Central? Last active yes Policy on tab? not just listed Heartbeat? to this XGS XGS evaluates rules top-down, first match No device / offline → Central Firewall match zones · service Action + NAT Accept · MASQ Heartbeat gate min HB / block none SD-WAN / VPN SLA or Connection Log on Destroy log_type + fw_rule_id GREEN CLOSE — assigned policy + permitted HB + intended rule + two-way path + log row Accept with no Destroy, or Active WAN with SLA fail, is not a close Official facts students invert 1. Sophos Firewall evaluates firewall rules, not rule groups. Groups only organise the table. 2. Auto-created MTA / IPsec / hotspot rules land at the top. A new Top rule can hide mail or a tunnel. 3. From SFOS 18, routing is SD-WAN policy routing. The firewall rule no longer carries the route. 4. Firewall logs on Destroy. Loss of internet can close a session with no log line. Do not invent Accept from an empty viewer. Sources: Firewall rules · Add a firewall rule · Log viewer · About Policies · Security Heartbeat

Read left → right, then the green close bar. Diamonds are Central questions. The XGS row is stamps after the first match.

#1 student trap — Base Policy exists, laptop is unprotected

Base Policy is the default catch-all. Official: later you check which policy was applied by opening the computer and looking at the Policies tab. A finance Peripheral Control or Threat Protection policy that is turned on in the list can still lose to a higher user policy, or never be assigned to this device. Existence is not assignment. Reset health status is not assignment either — it only clears old alerts so current issues show.

4. How to choose the next stamp

You are not choosing a product. You are choosing which floor prints the next stamp, and what proof you will quote.

ChoiceUse whenDo not use whenProof you were right
Fix in Central first Device missing, Last active stale, Agent mode = XDR Sensor only, Policies tab shows the wrong Threat Protection. The laptop is Online, policy is assigned, and Log viewer already cites fw_rule_id=14. Computers & Servers row + Policies tab names TP-Finance-Intercept.
Device policy vs user policy Device policy when the laptop must keep the recipe no matter who signs in. User policy when the person travels across machines. You create both and assume they merge. Official: the higher list item wins. That computer’s Policies tab shows the winner. Source: About Policies.
Intercept X (Endpoint / XDR) You need protection on the laptop. Agent mode Endpoint or XDR includes anti-malware. Heartbeat can then inform the XGS. You install XDR Sensor and expect Intercept X to block. Official: XDR Sensor is detection only — no Sophos protection. Agent mode column + Assigned Products on Summary. Sensor-only shows a warning when you pick it.
Heartbeat gate on the rule Minimum source HB = Yellow or Green for LAN→WAN finance. Block clients with no heartbeat when unmanaged devices must not use this door. You set Block clients with no heartbeat on a guest VLAN that has no Intercept X, then wonder why browsers die. Control center Security Heartbeat widget counts + the rule’s HB icons. Source: Add a firewall rule.
Action = Accept + Log firewall traffic Known LAN→WAN service you will have to prove later. Logging must be on in the rule and under System services → Log settings. A second Accept under a working match. Top-down already stopped. Auto-created IPsec / MTA rules may already sit above you. Log viewer Firewall module: fw_rule_id matches the rule you named.
SD-WAN SLA vs first available SLA (Best quality or Custom latency / jitter / loss) for SaaS that dies at 200 ms. First available when any live ISP is enough. You steer on a green gateway icon. Health-check up is not Custom SLA pass. In use is not “SLA met.” Routing → SD-WAN routes hover Active; SD-WAN Log viewer module; Historical performance.
IPsec Connection vs Active Quote Connection on Site-to-site VPN → IPsec when the site path is the tunnel. Active alone can be a half-built or idle object. You treat a green Active pill as “Pune can reach HQ.” Partial tunnels exist. Connection status + a matching firewall / SD-WAN hit. Source: IPsec connections.
Central Admin isolate vs Heartbeat block Admin isolate (Actions on the computer) when EDR/XDR/MDR says investigate this one host. Heartbeat block when the XGS must refuse a red / missing estate at the door. You isolate the fleet from Central because Outlook is slow. Isolation is not a WAN repair. Summary shows Isolated by Admin, or the rule’s HB action matches the widget.
Linked NAT is not a second firewall

Official: Sophos Firewall applies firewall rules before source NAT. A Create linked NAT rule SNAT is listed in NAT rules, tagged with the firewall rule ID and name. A NAT rule above that linked rule can still win. Default MASQ translates the original IP to the WAN interface IP (or the XFRM IP on some route-based VPNs). Deleting Default SNAT IPv4 is a trap — it reappears when you create or update a WAN interface. Turn it off if you must. Source: NAT rules + Add a firewall rule.

5. Runbook Side A → B → C

Lab values only. Central computer FIN-LAPTOP-22, last user finance.user@example.lab, client 192.0.2.25, SaaS 198.51.100.80:443, appliance XGS-LAB-2100, serial XGS2100LAB001, PAT 203.0.113.10. Nothing here is a live tenant.

Side A — Central device and the assigned policy

Primary source: Computers and servers + Computer Policies + Set up policies + Threat Protection Policy.

  1. Name the laptop, not the rumour

    My Environment → Computers & Servers. Filter Device name FIN-LAPTOP-22 or IP 192.0.2.25. Quote Health status, Last active, Agent mode, Tamper protection. Unknown health plus a grey Last active is an estate problem, not an XGS problem. Source: Computers and servers.

  2. Open the Policies tab

    Click the name → Policies. Official wording: this tab shows the policies that are applied to the computer. Quote Threat Protection = TP-Finance-Intercept. If you see only Base Policy and you expected a finance recipe, stop. Do not add an XGS Accept to compensate. Source: Computer Policies + Set up policies.

  3. Read the recipe, do not assume Intercept X

    My Products → Endpoint → Policies → Threat Protection. Confirm the policy is turned on. Device Isolation (red health) is a choice, not a default you invent. Recommended settings exist; Account Health Check can flag drift. Agent mode XDR Sensor means no Sophos anti-malware — Intercept X is not on that path. Source: Threat Protection Policy + Computers and servers Agent mode.

  4. Only then involve the XGS

    If Heartbeat will gate the firewall rule, the XGS must be registered with the same Central account and Central management / Security Heartbeat turned on. Path: XGS Sophos Central → Register (OTP or super-admin email), then Central My Products → Firewall Management → Firewalls. Status Not managed by Sophos Central means registered for Heartbeat only — group policy from Central will not push. Source: Enable Sophos Central management of Sophos Firewall.

Side B — Intercept gate, then the XGS stamps

Primary source: Add a firewall rule + Firewall rules + SD-WAN profiles / Managing SD-WAN routes + IPsec connections + Security Heartbeat.

  1. Stand on the XGS that will print the ticket

    System services → High availability if the pair exists. Active-passive: the primary processes traffic. An empty Live connections table on the auxiliary is not “the firewall has no sessions.” Register both HA devices from the primary (Central synchronization → Register both HA devices) when Central management is in play. Source: HA modes and device roles + Manage an HA pair in Sophos Central.

  2. Save Accept with logging and the Heartbeat gate

    Use the mock. Log firewall traffic is how this rule can ever appear in Log viewer or syslog. Heartbeat: Yellow permits green or yellow endpoints; Block clients with no heartbeat refuses laptops that never phoned this XGS. Endpoints that never sent a heartbeat are allowed unless you select both source and destination “block no heartbeat” options. Source: Add a firewall rule §10.

  3. Confirm NAT, then decide SD-WAN vs VPN

    Linked NAT appears in Rules and policies → NAT rules with this rule’s ID and name. Internet egress: MASQ is the default. Site path: Routing → SD-WAN profiles (health check + Service Level Agreement) then Routing → SD-WAN routes. Tunnel path: Site-to-site VPN → IPsec (policy-based uses the firewall rule + local/remote subnets; route-based uses XFRM + SD-WAN / static routes). Source: NAT rules + SD-WAN + Site-to-site VPN.

  4. Do not celebrate Save

    A saved rule is a recipe. Auto-created rules may now sit above Finance-HTTPS. Side C is the proof. Source: Firewall rules — review rule positions after every automatic or manual create.

Side C — prove the finished ticket in the log

Primary source: Log viewer + Log settings + Syslog guide for SFOS 21.5 + Managing SD-WAN routes + IPsec connections. Night-shift field list: evidence desk.

  1. Turn the recorder on before you replay

    Rule: Log firewall traffic already on. Box: System services → Log settings — Local reporting includes Firewall (and SD-WAN if you will quote that module). Central: XGS Sophos Central services if you expect the same logs in Central. Source: Log settings + Add a firewall rule logging note.

  2. Replay the business click, then open Log viewer

    Upper-right of any XGS page → Log viewer (new full-screen window). Module selector → Firewall. Add filter source IP 192.0.2.25. Official: the session appears when Destroy arrives. SSL/TLS rows appear after the handshake completes.

  3. Quote two fields, not a screenshot

    Detailed view: log_type (Firewall) + fw_rule_id (14) + action / status. If the user still sees a block page, switch module to Web or IPS — that is a later stamp on the same Accept, not a missing rule. Source: Log viewer + Syslog guide.

  4. If the Firewall module is empty, do not add Accept

    Official caveat: sessions closed without a Destroy (loss of internet) are not logged. Then the first tool is Routing → SD-WAN routes (hover Active) or Site-to-site VPN → IPsec (Connection), not a new Top rule. Confirm you are not on the HA auxiliary. Source: Log viewer “When are sessions logged” + Managing SD-WAN routes.

Proof · the log is the product
Teaches: operators close a Sophos ticket from a log field, not from a green shield
Notice: juniors photograph Intercept X. Seniors paste log_type, fw_rule_id, and Last active.
Dummy Log viewer detail — not a customer firewall
device="SFW" date=2026-08-16 time=10:44:12 timezone="IST"
device_name="XGS-LAB-2100" device_id=XGS2100LAB001
log_id=010101600014 log_type="Firewall" log_component="Firewall Rule"
log_subtype="Allowed" status="Allow" fw_rule_id=14
src_ip=192.0.2.25 src_port=51901 dst_ip=198.51.100.80 dst_port=443
src_trans_ip=203.0.113.10 proto=TCP user_name="finance.user"
hb_status="yellow"
Green success on this runbook

Computers & Servers: FIN-LAPTOP-22 Online, Health Good (or an explained Warning), Agent mode XDR. Policies tab: TP-Finance-Intercept. XGS rule 14 Accept, Log firewall traffic on, min source HB Yellow. Log viewer: log_type=Firewall fw_rule_id=14 with return bytes, or a documented SD-WAN / IPsec field if Destroy never arrived. That is working. Accept with an empty viewer is not.

6. Runtime — list order, auto-rules, missing heartbeat

After go-live the factory keeps moving. Central applies policies in list order — drag the most specific to the top. A new user policy can silently steal a laptop from your device policy. Re-open the computer’s Policies tab after every “we cloned a policy” change. Source: Set up policies + About Policies.

On the XGS, later packets of an allowed flow ride the connection the first match created. A new Accept underneath that match will not see them. Automatically created MTA, IPsec, and hotspot rules land at the top and are evaluated first. Creating another Top rule shuffles the table. Official warning: overlapping criteria can break mail delivery or stop a tunnel coming up. After every auto-create, re-read positions. Source: Firewall rules.

Heartbeat is timed. Missing heartbeats are detected only in the zones you list under Sophos Central → Optional configurations → Missing heartbeat zones. If the policy blocks a zone but that zone is not listed, the Control center widget can show Missing while you stare at the wrong VLAN. Endpoints that go to sleep sign out of Synchronized user ID — traffic then follows “unknown user” rules, not the finance group you expected. Source: Security Heartbeat + Synchronized user ID authentication.

SD-WAN: a gateway can be up (health check answered) and still fail Custom SLA (latency / jitter / loss). Hover Active on the route; read Historical performance. IPsec: Active is not Connection. A partial tunnel can look alive while one selector is down. Central SD-WAN connection groups use green / orange / red tunnel status — still not an XGS firewall Allow. Source: Managing SD-WAN routes + IPsec connections + Manage an SD-WAN connection group.

HA is two copies of the XGS floor. Green sync means the book copied. It does not mean Outlook recovered. Prove with the same click, on the new primary, and a new Log viewer row. Conn-sync enabled does not mean every UDP flow survived.

Web after Accept is still this factory

Firewall Accept plus a web-policy category block is two stamps, not a missing rule. DPI is the default engine; SSL/TLS inspection rules apply on detected TLS. Use web proxy instead of DPI only when you need SafeSearch, YouTube restrict, parent proxy, or caching. A pinned banking app that refuses the re-signing CA needs a Don’t decrypt / Local TLS exclusion — not SSL/TLS engine off. Source: Add a firewall rule Web filtering + SSL/TLS inspection rules.

7. Traps + Log viewer proof

SymptomLooks likeActuallyFirst move
Green tray shield, Outlook still dead Sophos is fine Tray ≠ Health status / Policies tab Computers & Servers, then Policies tab
Finance USB still mounts Peripheral policy broken Policy exists, not assigned (or user policy won) That computer → Policies tab
XDR Sensor, “Intercept didn’t block” Signature miss Agent mode is detection-only Agent mode column — Endpoint or XDR
Accept + spinning browser Missing rule No return path, or no Destroy log yet Log viewer bytes; then NAT / SD-WAN / server
Added Top Accept, mail died SMTP server Auto MTA rule no longer first Review rule positions
SaaS slow, both WANs green Need a new Accept Health-check up, SLA fail SD-WAN Active + Historical performance
Pune “VPN is up” IPsec Active Connection down / partial tunnel IPsec Connection status
Empty Live connections No policy You are on the HA auxiliary System services → High availability
Empty Log viewer, session on screen Sophos hid the block Logging off, or no Destroy (WAN died) Log settings, then SD-WAN / IPsec
Unmanaged laptop hits finance rule Need another Drop No heartbeat, block-none not set Block clients with no heartbeat on that rule
Proof checklist — Finance-HTTPS is actually working
Interview close you can steal

Sophos is a Central + XGS policy factory. I prove the device and the assigned policy first. Intercept X plus Security Heartbeat is the intercept stamp, not a second firewall. The XGS then matches a firewall rule, an SD-WAN SLA path, or an IPsec Connection. I close with Log viewer log_type and fw_rule_id. A green shield is not health. Accept is not the log.

Five night-shift tickets mapped to first tool + one official field are on Prove Sophos is working — the evidence desk. Practice the same isolate-then-quote discipline on the Sophos dummy lab.

Knowledge check

Six judgment questions. Mapped to assignment, intercept, Accept-is-not-the-log, SLA vs up, IPsec Connection, and empty Destroy. Check, then reset.

Q1

Finance says the laptop is “not protected.” TP-Finance-Intercept exists and is turned on under My Products → Endpoint → Policies. First proof?

Correct: b. Official: Computers → name → Policies tab shows what is applied. Existence in the list is not assignment. Reset health only clears old alerts. Re-read Mental model and Side A.
Q2

What is Intercept X + Security Heartbeat on this factory?

Correct: c. Heartbeat is Configure Synchronized Security Heartbeat on Add a firewall rule. XDR Sensor explicitly does not install Sophos protection. Re-read Mental model and How to choose.
Q3

Log viewer shows fw_rule_id=14, status Allow, 1904 bytes sent, 0 received. The user still spins. First move?

Correct: a. Allow without return bytes is a printed ticket with a dead return half. Re-read Why a green shield is not a session and Side C.
Q4

Both WAN gateways are green. SaaS is slow. SD-WAN Historical performance shows ISP2 failing Custom SLA. What is true?

Correct: d. From SFOS 18 routing is SD-WAN policy routing. Health-check up is not Custom SLA pass. Re-read How to choose and Runtime.
Q5

Pune lost HQ apps after a peer change. Someone says “IPsec is Active.” Firewall Log viewer for that subnet is empty. Best first proof?

Correct: b. Official Log viewer: no Destroy on WAN loss. IPsec Active is not Connection. Re-read Side C step 4 and Runtime.
Q6

What proves Finance-HTTPS is actually working?

Correct: c. Assignment + intercept + path + log. Accept and a tray icon are recipes, not the finished ticket. Re-read Side C and the proof checklist.

Sources

Related: Prove Sophos is working — the evidence desk · Sophos Firewall hub · Dummy lab · All lessons

Dummy lab data only. Confirm current field names on the production Central and SFOS release before you type on a real estate. HA conn-sync enabled does not mean every UDP flow survived.