Sophos X-Ops threat feeds
Sophos X-Ops threat feeds is a SophosLabs-managed global threat database that's regularly updated and pushed to the firewall. The firewall blocks all requests and traffic matching this database of malicious IP addresses, domains, or URLs.
Sophos X-Ops threat feeds are turned off by default.
Requirements
- For license requirements, see Licenses for threat feed modules.
 - For additional configurations required for all threat feed modules, see Firewall configurations for threat feeds.
 
Configure Sophos X-Ops threat feeds
- Go to Active threat response > Sophos X-Ops threat feeds.
 -  
Turn on Sophos X-Ops threat feeds.
The firewall scans traffic for the IP addresses, domains, and URLs in the threat feed.
 -  
Select the action from the following options:
- Log only: Only logs threats.
 - Log and drop: Logs and blocks threats.
 
 -  
Click Apply.
 
More resources