Central Firewall - no Sophos Services and FQDN - why?

When going to Hosts and Services in Sophos Central, you pre-configured a lot of 3rd Party stuff there but forgot to pre-configure your own services.

So why is there no FQDN group for Sophos Services? There are all the other vendors and your'e maintaining them more or less... 

https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/DomainsPorts.html

So now I want to prepare some firewalls rules for Sophos devices and need a lot of time to implement all these FQDN manually. That could have been done better.

You cannot handle everything by built-in TLS Exception URL groups.

Top Replies

  • in reply to LHerzog +2 suggested

    Hi, 

    The default design choice in the SFOS is that users will allow outbound traffic for web (http/https) and then use the web filter to restrict and protect it. This security stance works for the majority of our customers. However, for those that desire to have a stricter firewall rule policy (limiting http and https traffic at the perimeter without using the web filter) a bit more work is needed to configure this. Basically, the Sophos URLs are auto excluded in our web filter. So you could allow 80 and 443 outbound and turn on the web filter and restrict everything but Sophos would still be accessible.

    Does that answer your question?

    Jump to answer