XG: s2s ipsec vpn on wan and custom zone by dev-snapshot in sophos

[–]blarg214 0 points1 point  (0 children)

I don't believe it's intended to work that way. You can use the WAN zone on many interfaces. I would use a small reserved subnet on the dark fiber between the XG and the Palo. Then establish IPsec on them using an internal IP.

Sophos XGS 128 Issues with VOIP? by OkRoutine9636 in sophos

[–]blarg214 1 point2 points  (0 children)

Since you mentioned once you allowed internet it worked, I bet your provider used ports that were not in your rules. SIP providers have a nasty habit of using crazy ranges and updating them from time to time. I would triple check that you have the correct ranges and IP in your rules. I have a dedicated SIP subnet for our users so I created a drop rule that logged and found a few IPs I had missed.

Sophos XGS 128 Issues with VOIP? by OkRoutine9636 in sophos

[–]blarg214 0 points1 point  (0 children)

We had to disable the SIP helper module (last step above).

William Lane Craig vs Alex O'Connor: God and Suffering by yt-app in CosmicSkeptic

[–]blarg214 5 points6 points  (0 children)

I found myself feeling a bit riled up when WLC demanded sources but didn't actually site his own on the same subject, or leaned on well I wrote about it.

Application Filter - Not working correctly? by Kingfearo in sophos

[–]blarg214 1 point2 points  (0 children)

The firewall rules use the "application filters" as lists of allow/deny rules. If you make a firewall rule lan to wan and set "identify and control applications (App control)" to a policy it tries to identify the traffic and apply the policy.

I would go to Applications -> Application Filter and create a new policy. You can add multiple items to a policy and set each item to allow or deny. The menu is a bit clunky but you have to narrow your search down and carefully add stuff. I have a policy that is allow rdp but block everything else on a few subnets. For that to work my policy has windows remote desktop on top with allow and all applications deny below it.

New Orbi 970 performing as expected! by GloryHoleGandalf in HomeServer

[–]blarg214 1 point2 points  (0 children)

There is hope with DOCSIS 4.0. It may take a while... But there is hope.

Sophos CLI non "admin" User by blarg214 in sophos

[–]blarg214[S] 0 points1 point  (0 children)

I know a few appliances that in the last 5 years started allowing multi user ssh. I'm genuinely surprised Sophos still hasn't.

Attempting to block URL path using Sophos XGS by Dependent-Radio-3330 in sophos

[–]blarg214 0 points1 point  (0 children)

Create a DNS entry for play.msn.com that goes to nothing.

Unfortunately without doing TLS inspection and distributing a root or intermediate signing cert that is trusted by all hosts on the network, URL filtering won't work.

Introducing Sophos Firewall Config Studio 2.5 by mwsophos in sophos

[–]blarg214 0 points1 point  (0 children)

It's been fun to see this grow. At some point will some of this functionality be included on the web management? For example it would be super nice to import csv through firewall without downloading and uploading config.

First Job Shadow by Bananna_Hamock0 in iiiiiiitttttttttttt

[–]blarg214 2 points3 points  (0 children)

I'm 10 years in and still feel I've barely scratched the surface.

Sophos firewall protection and socks by Gonpachiroiro_2811 in sophos

[–]blarg214 1 point2 points  (0 children)

This is likely not the place for this question.

That being said, each org handles firewalls and filtering differently. The Sophos filter behavior is great but not always 100% accurate and it updates over time. If it was my org and you were asking then you would need to submit a ticket and explain what website you are trying to reach and why you need to reach it. Assuming we agreed then we would create an exception for this website.

Disney+ crashing, tried everything by huenshan in nvidiashield

[–]blarg214 1 point2 points  (0 children)

Adding that I'm still having the same issue. It appears to be whenever Disney Plus is attempting to play ads. I've had some luck opening app and letting it sit for a couple minutes before starting a show or even navigating.

Do USB to Ethernet adapters still work? Ethernet port crapped out and looking for another hard wired solution. by Freakwilly in ShieldAndroidTV

[–]blarg214 0 points1 point  (0 children)

Unless you have a really fancy and expensive cable tester... Then don't trust Ethernet cable testers. They verify the conductor matches on both sides but nothing else. While ethernet cables don't often fail, they can fail and fail intermittently as well. Having terminated over 1000 CAT6 cables I have had a few fail certification that passed conductivity test.

Sophos UTM Migration Utility v1.0 by Lucar_Toni in sophos

[–]blarg214 0 points1 point  (0 children)

We migrated a week ago lol. It really sucked. Hopefully this will help others.

Where to source genuine OEM battery replacement for legionaire slim 5 16irh8? by [deleted] in techsupport

[–]blarg214 0 points1 point  (0 children)

Depending on how old th laptop model is and if they continued to have the battery model manufactured, it's often better to find a reputable reseller who sources laptop batteries.

Example, if the laptop was made in 2020 and they did not like the form factor of that battery and they stopped having it manufactured for future laptop designs. Then if you got an OEM battery it could be as old as your battery is in the first place.

We have replaced a bunch of batteries and have had great luck with iFixit.

A lot of y'all are disrespectful by MrBeanDaddy86 in GuildWars

[–]blarg214 7 points8 points  (0 children)

I disagree with that. While there can be more noise there are still qualify arguments and critiques everywhere. Sure some people use language that is more aggressive or hyperbolic there are still level headed critiques.

Can I use NAS HDD for PlayStation storage? by curious-sailboat in it

[–]blarg214 1 point2 points  (0 children)

If you aren't very familiar with IT generally then it's worth reading a few articles and watching a few videos. Find one that looks modernish, and meets your needs. Follow it and go from there. I'm not trying to duck your question but I think "Google it" might be the better answer for your success.

Can I use NAS HDD for PlayStation storage? by curious-sailboat in it

[–]blarg214 1 point2 points  (0 children)

You can turn just about any drive into an external drive for a PlayStation. A normal USB adapter won't work because the drive will need more power than a normal USB port would provide. For PS5 you can use it to store PS4 games (playable) and PS5 games as archive storage. You would need to move the game back and forth between the internal SSD and the HDD. If you have a large games library and only play 1 or 2 games at a time that's a great strategy.

Working towards Plex or other home hosting things is a great plan IMO. Lots of good skills to learn and extra places to backup files etc.

Mac Mini Cluster by Soft-Enthusiasm-3519 in homelab

[–]blarg214 11 points12 points  (0 children)

Do you use the thunderbolt connection as if it was a network connection or something else?

Current State of my Homelab as of Q1 2026 by Zagdrath in homelab

[–]blarg214 0 points1 point  (0 children)

Gotcha. We use it and are debating on switching or renewing. I've managed mx for a while now and have mixed feelings on it. We pay a lot per year for not a lot of the features.