What Myrmex Can Do
Read & troubleshoot
Inspect system status, interfaces, routing, firewall rules, web and app filtering, NAT, and VPNs — read-only diagnostics, pulled live.
Hardening audit
Run a Security Posture audit against the device’s SFOS hardening controls.
Policy hygiene
Find shadowed, unused, or overly-permissive firewall rules and propose cleanups.
Backup & diff
Back up the configuration on demand and compare revisions over time; with approval, apply rule and VPN changes.
Before You Start
- A Collector deployed on a network that can reach the firewall’s management IP over SSH. See Deploying the agent.
- SSH enabled on the Sophos Firewall for the zone the Collector connects from.
- An administrator account Myrmex can use to log in (a read-only profile is enough for analysis; a read-write profile is required to apply changes).
Step 1 — Create the Access Account on Sophos Firewall
1
Enable SSH access
In Administration → Device Access, enable SSH for the zone the Collector connects from (for example LAN).
2
Create an admin profile (optional, recommended)
In Profiles → Device access, create a profile scoped to what Myrmex should do — read-only for analysis, or read-write to allow changes.
3
Create the administrator
In Authentication → Users, add a user with a strong password and assign the admin profile above, ensuring it can reach the console. Note the username and password — you’ll enter them in Myrmex.
Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → Sophos Firewall, then fill in:Connect
Click Connect to validate the SSH connection and finish. The firewall then appears under Environment → Integrations, and you can start asking the AI about it in the Workspace.This integration is operated by the Integration Specialist agent, which runs the SFOS console on your behalf. Browse more connectors in the Integrations directory.