This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Assign built-in services to IP and not to zone - HELP NEEDED to reconsider the feature request

Using ACL, on XG, is possible to assign services to zone and not to IP. How can we restrict services like:

MTA

L2TP

PPTP

SSL VPN

USER PORTAL

to a specific IP?

This Feature request has been closed:

https://ideas.sophos.com/forums/330219-xg-firewall/suggestions/16593775-assign-the-built-in-services-vpns-admin-etc-to

This feature is a must and ALANT closed it (already possible). Please reply here and add your own comments.

Thanks



This thread was automatically locked due to age.
Parents
  • Hi,

    correct me if im wrong, but you can use the local Service ACL Exception Rule instead of the checkbox page in device access.

    So you untick the checkbox for SSL vpn on WAN and create a local Service ACL Exception Rule which allows on Zone ANY and a special IP the SSL VPN.

     

     

    But you are right, there are not all of you requested Services.

     

    Cheers

Reply
  • Hi,

    correct me if im wrong, but you can use the local Service ACL Exception Rule instead of the checkbox page in device access.

    So you untick the checkbox for SSL vpn on WAN and create a local Service ACL Exception Rule which allows on Zone ANY and a special IP the SSL VPN.

     

     

    But you are right, there are not all of you requested Services.

     

    Cheers

Children
  • @ManBearPig

    I have to recject your answer. As I wrote, we know about the ACL menu (which I do not like at all, but this is my opinion) but most of the service are not there. For SSL VPN, the option should be on VPN Show settings menu (one location) and not in multiple location (one to activate the vpn, one to bind the service, one to create SSL VPN profile). So please report the missing services and improve the ACL menu

    Thanks