This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall

This is probably more of a case that I havent configured the policy correctly, but I thought I would post in here anyway just in case it something obious I have missed.

Ok, so I have rolled out Sophos for my company, its only about 26 PC (small company), I originally just pushed out the AV as I needed to test the Firewall, Tamper Protection and Web Control before unleashing it onto everyone, then struggling with problems arising from that. I rebuilt an old PC that I had spare with Windows 7, put it into the company domain (in a separate OU from everywhere else). I have installed Sophos AV, applied the policy, works fine as expected.

So I then enabled the Tamper and Web Protection to see how that works, fine.

I have now pushed out the Sophos Firewall to this one PC and have applied a newly created policy its a custom policy that allows outbound traffic (as I dont want the users every 5 seconds being asked if this is allowed), all of the blocking options are enabled, I have trusted the LAN settings (there is only one LAN here) and I have allowed fle and print sharing. So everything is setup as I would expect it to work.

Now the problem I have is that when I first turned this PC on this morning, it took an age to login (sat at the W7 Welcome screen for a good few minutes) then once it was in windows it didnt have an IP (couldnt get to DHCP) and Sophos was in a failed updating state. So I am assuming that something on the firewall is blocking access to DHCP so it cant update Sophos. 

Although if I manually click on Sophos in the system tray and tell it to update, it does evetually do it and I have to reboot and then the PC works as it should (i.e. it retrived the updates and firewall policy so it all happy). 

But surely this cant be the case, if I push out the firewall to everyone else? 

I am pretty sure it is something in the policy that I havent done right.

Hopefully this makes sense to someone.

:47741


This thread was automatically locked due to age.
  • Hello DerrickML,

    [it] couldn't get to DHCP

     DHCP is permitted in the default settings and unless you have deliberately turned it off it's supposed to work. If it couldn't obtain an address first - why did it apparently work later?

    it retrieved the updates and firewall policy

    Updating and retrieving a policy are different things. Furthermore, the policy should persist and thus it shouldn't be necessary that a policy is received. As the stored and received policy are identical it shouldn't make a difference. BTW: Do you use Local network (detected automatically) in the LAN tab?

    As said, DHCP is supposed to work as it is permitted in the default rules for services.exe and svchost.exe. You did reboot after installing SCF - didn't you - and had no issues then? Or was it immediately after the initial reboot that you had this problem? Does the PC work now as expected and does it correctly obtain an IP (even after being off for some time)?   

     Christian

    :47791