Sophos X-Ops threat feeds
Sophos X-Ops threat feeds is a SophosLabs-managed global threat database that's regularly updated and pushed to the firewall. The firewall blocks all requests and traffic matching this database of malicious IP addresses, domains, or URLs.
Sophos X-Ops threat feeds are turned off by default.
Requirements
- For license requirements, see Licenses for threat feed modules.
- For additional configurations required for all threat feed modules, see Firewall configurations for threat feeds.
Configure Sophos X-Ops threat feeds
- Go to Active threat response > Sophos X-Ops threat feeds.
-
Turn on Sophos X-Ops threat feeds.
The firewall scans traffic for the IP addresses, domains, and URLs in the threat feed.
-
Select the action from the following options:
- Log only: Only logs threats.
- Log and drop: Logs and blocks threats.
-
Click Apply.
More resources