Clariti Docs
Credentials5 minutes· easy

Sophos XG/XGS Firewall

Network Security

The Sophos Firewall adapter connects to Sophos XG or XGS firewalls to pull network device configuration, interface status, and zone mappings into Clariti for network perimeter visibility.

What Clariti Collects

What You'll Need

  • Administrator access to the Sophos XG/XGS firewall web interface
  • API access enabled on the firewall
  • The firewall hostname or IP address accessible from Clariti
  • ~5 minutes to complete setup
  • Your Clariti account with adapter management permissions

Get Your Credentials

Log in to the Sophos XG/XGS firewall web admin console. Navigate to Backup & Firmware > API and ensure the API configuration service is turned on.

For authentication, the adapter uses the same administrator credentials you use to log in to the firewall web interface. For security best practice, create a dedicated read-only admin account:

  1. Go to Authentication > Users and create a new user
  2. Assign the user an administrator profile with read-only access
  3. Use these credentials in Clariti

You will also need the firewall's hostname or IP address that Clariti can reach over HTTPS.

Enter Credentials in Clariti

Value from vendor consolePaste into Clariti field
Firewall admin usernameUsername
Firewall admin passwordPassword
Firewall hostname or IPHost

Verify Connection

Click Test Connection in Clariti. A successful connection returns a green checkmark. The first data sync typically completes within a few minutes.

Troubleshooting

  • 401 Unauthorized — Verify the admin username and password are correct. Password changes on the firewall require updating credentials in Clariti.
  • 403 Forbidden — Ensure the API service is enabled on the firewall and the admin account has appropriate access permissions.
  • Timeout — Verify the firewall management interface is network-reachable from Clariti over HTTPS (port 4444 by default). Clariti retries automatically.