Sophos Threat Feed Integration Guide

OpenDBL threat intelligence blocklists can be imported into Sophos Firewall (SFOS / XGS Series) using native Threat Intelligence External Feeds, and into Sophos UTM 9 (SG Series) via automated HTTP/S Network Definitions.

Sophos Firewall (SFOS / XGS Series) Integration

Sophos SFOS supports native HTTPS external IP threat intelligence feeds updated automatically on a schedule.

1

Add External Threat Feed Object

In Sophos Firewall Admin Console, navigate to Configure > Network > Threat Feeds (or System services > Threat intelligence) and click Add.

2

Configure Feed Details

Set Name (e.g. OpenDBL_IPSum), select Type as IP address list, enter the feed URL (e.g. https://opendbl.net/lists/ipsum.list), and set Update frequency to Every 15 minutes or Hourly.

3

Enforce in Firewall Rules

Under Protect > Rules and policies > Firewall rules, edit your inbound/outbound rules and select the OpenDBL Threat Feed object in the Source networks or Destination networks field with Action set to Drop or Reject.


Sophos UTM 9 (SG Series) Integration

Sophos UTM 9 supports importing external IP feeds via automated Network Group definitions or Web Protection policy objects.

1

Create Network Definition Object

In WebAdmin, go to Definitions & Users > Network Definitions > Network Definitions and click New Network Definition.

2

Configure Dynamic List Source

Set Type to DNS Host or Network Group, specify the OpenDBL list endpoint (e.g. https://opendbl.net/lists/blocklistde-all.list), and save.

3

Apply to Firewall Policy

In Network Protection > Firewall > Rules, add a drop rule with the OpenDBL network object as Source or Destination.