This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint Security

We are testing the Sophos Enterprise Console version 5, how to implement firewall policy for laptop user while they disconnected from our network. If they connect private internet and transfer the files from office laptop to third party storage provider. How can we block the file transfer for this scanario?. Kindly confirm how to implement this test case.

Thanks N regards,

Magesh Kumar .P

:22873


This thread was automatically locked due to age.
Parents
  • Hello Magesh,

    a firewall (SCF or other) likely won't help you here (unless you completely block internet access). The reason is that firewall rules are usually address based (even though you can enter host or network names) because "real-time" name resolution is not feasible. With the ever increasing number of providers (some of which use large distribution networks) it is impossible to compile a list of all and all their addresses. While a firewall can be used to block certain applications (i.e. executables) it'd be all but impossible to control transfer via browsers.

    SESC offers two features which are probably better suited to tackle your problem: One is Application Control with which, among others, a number of Online Storage applications can be blocked. It also makes it possible to specify which browser(s) is/are permitted. The other is Data Control which can block uploads for certain browsers and IMs.

    HTH

    Christian

    :22883
Reply
  • Hello Magesh,

    a firewall (SCF or other) likely won't help you here (unless you completely block internet access). The reason is that firewall rules are usually address based (even though you can enter host or network names) because "real-time" name resolution is not feasible. With the ever increasing number of providers (some of which use large distribution networks) it is impossible to compile a list of all and all their addresses. While a firewall can be used to block certain applications (i.e. executables) it'd be all but impossible to control transfer via browsers.

    SESC offers two features which are probably better suited to tackle your problem: One is Application Control with which, among others, a number of Online Storage applications can be blocked. It also makes it possible to specify which browser(s) is/are permitted. The other is Data Control which can block uploads for certain browsers and IMs.

    HTH

    Christian

    :22883
Children
No Data