Sophos Firewall & UTM Integration Guide
Sophos Threat Feed Integration Guide
OpenDBL threat intelligence blocklists can be imported into Sophos Firewall (SFOS / XGS Series) using native Threat Intelligence External Feeds, and into Sophos UTM 9 (SG Series) via automated HTTP/S Network Definitions.
Sophos Firewall (SFOS / XGS Series) Integration
Sophos SFOS supports native HTTPS external IP threat intelligence feeds updated automatically on a schedule.
Add External Threat Feed Object
In Sophos Firewall Admin Console, navigate to Configure > Network > Threat Feeds (or System services > Threat intelligence) and click Add.
Configure Feed Details
Set Name (e.g. OpenDBL_IPSum), select Type as IP address list, enter the feed URL (e.g. https://opendbl.net/lists/ipsum.list), and set Update frequency to Every 15 minutes or Hourly.
Enforce in Firewall Rules
Under Protect > Rules and policies > Firewall rules, edit your inbound/outbound rules and select the OpenDBL Threat Feed object in the Source networks or Destination networks field with Action set to Drop or Reject.
Sophos UTM 9 (SG Series) Integration
Sophos UTM 9 supports importing external IP feeds via automated Network Group definitions or Web Protection policy objects.
Create Network Definition Object
In WebAdmin, go to Definitions & Users > Network Definitions > Network Definitions and click New Network Definition.
Configure Dynamic List Source
Set Type to DNS Host or Network Group, specify the OpenDBL list endpoint (e.g. https://opendbl.net/lists/blocklistde-all.list), and save.
Apply to Firewall Policy
In Network Protection > Firewall > Rules, add a drop rule with the OpenDBL network object as Source or Destination.