Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG450 Locally signed Certificate for LAN IP

I've been trying to get locally signed Certificate to work for the firewall's LAN IP. Unfortunately with all effort i tried, microsoft edge still consider firewall's page as non-secured. However when switched to public ip instead, it works. 
Currently on XG450 firmware SFOS 18.5.4 MR-4-Build418

The below doesn't work.


This work however.




is LAN IP not workable ?



This thread was automatically locked due to age.
Parents Reply Children
  • I did followed the settings exactly like what you mentioned.
    However, it didn't work out. Which is why i find it weird.
    According to my understanding , locally signed certificate shouldn't be that difficult.
    That's why i wanted to know if there's a way to find where i configured wrong.
    I believe the KB articles had some missing info.
    Assumingly the kb was done to only cover sophos xg firewall for those who already know how to configure it.
    However, some details are seriously lacking.

  • What did you set as the 'Common Name' while creating the self-signed certificate and how do you access the firewall? Via IP address or by any fqdn? 
    Your input will be valuable in regards to adding the details in the kB, please share with us !

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • As for common name, i just set it as XG450 which is not a hostname.


    This is what i configured. I used the first internal interface.

  • Okay what is the hostname set under Administration > admin and user settings > hostname ?
    And if it is the same, then download the default cert from certificate > certificate authorities and install that under the trusted root ca:

    1. Open Microsoft Management Console and enter MMC in Run.
    2. Click File Add/Remove Snap-in.
    3. Select Certificates from the list and click Add.
    4. Select Computer Account and click Next.
    5. Click Finish and OK.
    6. Expand the list of certificate containers.
    7. Right-click Trusted Root Authorities > All Tasks > Import.
    8. Import the recently downloaded certificate.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • keep the hostname and common name the same !!
    And what is the common name in default cert is it different ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.