Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Signature Sinkhole

Firmware version 17.0 have this signature but firmware version 18.5, 19.0, and 19.5 do not have this signature. Can anyone have firewall firmware version 19.5.1 and search in IPS policies have this signature and capture image reply me pls..

Thanks in advance.



This thread was automatically locked due to age.
Parents Reply Children
  • Hello there,

    Thank you for contacting the Sophos Community.

    Can you share the Case ID, that you opened with us, I see Case 06341469 under your account,t but I don't see any email where Sophos Support states that the IP signature you mention is supported.

    Currently, version 19.5 MR1 doesn't have that IP Signature. 

    Regards,

  • My case number is 06341469.I used to talk to Mr. Kris... M he said I have to upgrade firmware to 19.5.1 the problem will resolve but I have some exam from firmware version 19.5.1 don't have signature sinkhole. I wonder why firmware version 17.0 have sinkhole signature.

    Picture1 version 19.5.1 it gone. and picture 2  have sinkhole from version 17.0. 

    If you said 19.5. mr1 doesn't have that ip signature so if I want to use DNS sink hole how can I use it in sophos firewall.

  • Hi  The solution is released with signature pack X.20.28 (28th Mar 2023 ) and I have confirmed in my lab firewall that the signature is now available for "MALWARE-CNC Torpig bot sinkhole server DNS lookup (SID 16693)".