There were some discussions in past about special signs in rest api admin password. For instance https://community.sophos.com/xg-firewall/f/discussions/124256/sophos-xg-firewall-rest-api-authentication-with-special-characters
Today I found this :
when I used this password at XG with 18.0.4
QQ88Yjhjk&JKH87Etw.65
I got this message : <Status code="529">Input request file is Invalid</Status>
If I used name and password for login via GUI (internet explorer), I was successful.
I found out that sign & was the reason. When I substitute it with other sign (\) I am able to use REST API with account ...
This thread was automatically locked due to age.