Skip to content

Manage URL regex patterns with Config Studio

Use Config Studio to create, update, and validate URL regular expressions (regex) in web exceptions. You can export and import web exceptions between the firewall and Config Studio to simplify creating and updating them.

Use Config Studio to create regex patterns

Use Config Studio to create URL regex patterns for web exceptions, download the configuration, and import it into the firewall.

Create URL regex patterns

Create URL regex patterns for web exceptions in Config Studio.

  1. To open the tool in your browser, click Sophos Firewall Config Studio.
  2. Click the Configuration editor panel.
  3. Go to Rules > Web exceptions.
  4. Click Add.
  5. Enter a name.
  6. Under Skip these checks, turn on any of the following options:

    • Skip HTTPS decryption
    • Skip policy check
    • Skip cert validation
    • Skip malware scan
    • Skip zero-day protection
  7. Under Match by URL/Domain, select one of the following options:

    • Domain + all subdomains
    • Exact host only
  8. Enter the domain name in the text box, for example, example.com.

    The generated regex pattern and a preview appear automatically.

    Add domain name to automatically create web exceptions regex pattern.

  9. Click Add to URL Regex list.

    The patterns appear under URL Regex Patterns.

    Regex list in Config studio.

  10. Optional. Under URL Regex Patterns, you can click + Add URL regex and add a pattern directly.

  11. Click Add at the bottom of the slider.

Download web exceptions

Download the web exceptions configuration from Config Studio for import into the firewall.

  1. Click Download at the top.
  2. Click Download TAR and save the .tar file to your endpoint device.

    Download web exceptions in Config Studio.

Import exceptions into firewall

Import the downloaded web exceptions configuration into the firewall.

  1. In the firewall, go to Backup & firmware > Import export.
  2. Under Import, click Browse and select the .tar file.
  3. Click Import.
  4. Go to Web > Exceptions and check the entry.

Troubleshoot URL regex patterns with Config Studio

Use Config Studio to identify and fix incompatible URL regex patterns in existing web exceptions. Export the configuration from the firewall, import and fix incompatible patterns in Config Studio, and import the updated configuration back into the firewall.

Export web exceptions

Export web exception configurations from the firewall.

  1. Go to Backup and firmware > Import export.
  2. Select Export selective configuration.
  3. Enter Exception to search, then select WebFilterException and click Apply selected items.
  4. Click Download and save the .tar file to your endpoint device.
  5. Extract the file.

    The extracted folder contains the Entities.xml file.

Import and fix web exceptions in Config Studio

Import the exported web exceptions configuration into Config Studio and fix incompatible patterns.

  1. To open the tool in your browser, click Sophos Firewall Config Studio.
  2. Click the Configuration editor panel.
  3. Go to Rules > Web exceptions.
  4. Click Import in the upper right corner.
  5. Drag and drop the Entities.xml file, or upload it.

    The exceptions appear in Config Studio.

  6. In the Config Analysis column, look for entries labeled Bad regex.

    See the Bad regex entries in Config Studio.

  7. Click the Edit button.

    The entry appears under URL Regex Patterns.

  8. Click Apply Fix.

    Apply fix for bad regex in Config Studio.

  9. Click Update.

Download updated web exceptions

Download the updated web exception configurations from Config Studio.

  1. Click Download at the top.
  2. Click Download TAR and save the file to your endpoint device.

    Download the web exception in Config Studio.

Import updated exceptions into firewall

Import the updated web exception configurations into the firewall.

  1. In the firewall, go to Backup & firmware > Import export.
  2. Under Import, click Browse and select the .tar file.
  3. Click Import.

    The firewall imports the file and updates the existing web exceptions. If you changed the name of an exception, the firewall creates a new web exception instead of updating the existing one.

  4. Go to Web > Exceptions and check the entry.