Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

unable to successfully enable Sophos UTM9 Sandstorm. What's missing ?

Hello,

I have licensed and activated "Sophos Sandstorm" in "Sophos UTM9 9.409-9",
but even after downloading malicious files, the Sophos Sandstorm does not report
any activity. What's missing ? How to activate and test Sophos Sandstorm ?

To activate I have done the follwoing:

1. Enabled Licesing: sandstorm.
2. Web Protection: Web Filtering Actions:
Checked: Use Antivirus Scanning
Checked: Dual Scan
Checked: Refer suspicious items to Sophos Sandstorm
3. Email Protection:SMTP: Malware Scanning:
Checked: Malware Action: Quarantine
Checked: Dual Scan
Checked: Enable Sandstorm
4. Checked: Daemon /var/chroot-http/usr/bin/sandboxd is running
5. Checked: ping sandbox.sophos.com
6. Checked: telnet sandbox.sophos.com 443
7. Checked: System Settings: Single Scan Engine: Sophos
8. Checked: Send suspicious content to SophosLabs for analysis

 

Test to download malicious software from
http://sophostest.com/
www.sophos.com/.../sandstorm-test.aspx


But still:
- No Entries in sandboxd.log
- In Dashboard: Sandstorm: 0 malicious items detected
- Advanced Protection: No Activity reported from Sophos Sandstorm Activity
- No sandstorm Activity reported in /var/log/smtp.log
- No entry sandbox in http.log
- No entry sandstorm in smtp.log

What's missing ? How to successfully activate and test Sophos Sandstorm ?



This thread was automatically locked due to age.
Parents
  • Hallo Andre and welcome to the UTM Community!

    Let's hope one of the Sophos folks shows up to answer your question.  My lab UTM reports both links in sophostest.com triggered a send to Sandstorm but that they were not malicious.  I guess that Sandstorm is smarter than the tests. [:)]

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hallo Andre and welcome to the UTM Community!

    Let's hope one of the Sophos folks shows up to answer your question.  My lab UTM reports both links in sophostest.com triggered a send to Sandstorm but that they were not malicious.  I guess that Sandstorm is smarter than the tests. [:)]

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data