What the Sophos Audit Checks
Paste or upload your running configuration โ analysis happens entirely in your browser, your config is never uploaded to our servers.
AuthenticationManagementInterfaceSystem HardeningVPNIPSSSL InspectionWeb ProtectionFirewall PoliciesPoliciesLoggingUpdatesGeo-Blocking
Common Sophos Findings We Catch
CriticalWeb admin HTTPS only โ HTTP disabled
Allowing plain HTTP to the admin console exposes login credentials and session data to anyone able to observe network traffic.
Fix:
Fix:
โ
Administration > Device Access > disable HTTP, enforce HTTPS only for WebAdmin.
CriticalTwo-factor authentication enabled for admin
Without 2FA, a single leaked or guessed admin password is enough for full device compromise.
Fix:
Fix:
โ
Enable TOTP-based two-factor authentication for all administrator accounts.
HighIPS policy applied to all firewall rules, not left default
Firewall rules without an IPS policy applied pass traffic without intrusion-detection inspection, leaving a blind spot for exploit attempts.
Fix:
Fix:
โ
Apply an IPS policy to every firewall rule permitting traffic, not just a subset.
Audit Your Sophos Firewall Now
Paste your config, get a scored report with exact fixes in seconds.
๐ Start Free Audit