This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Home testing - Sophos XG 17.1 - its so easy?

Been running UTM Home edition for a while now (since 2016) and I recall the pain involved in originally setting it up for home use.

Multiple media devices, Hive hub, VPN use for work - I recall getting sick of it all and just creating an exception group and dumping MAC addresses in there to bypass the firewall and basic HTTP scanning. Eventually basic web traffic scanning was stopped as the kids went mental with roblox.

Minecraft was a nightmare to get working for the kids etc etc. - all this stuff required a huge amount of time and effort in creating rules etc.

 

Come yesterday I decided to move with the times and migrate to XG using a clean build.

Printed out a config of the existing UTM (to PDF), 

Installed 17.08MR - connected up, updated firmware etc through the wizard - all went well, a bit too well!!!

 

Everything was literally back up and running two hours later - HTTP scanning is enabled with web policy on the default policy and EVERYTHING just works.

Even the infamous Minecraft JUST works on me daughters PC!

Just had to configure WAF for use with my Synology box - easy enough!

 

Have to say I'm impressed - but what gives? I recall the days of having to create exceptions for media devices, android phones etc. Not had to do this once! - or am I doing this all wrong with the default profiles? :) - usually everything is blocked by default.....

Interested in experiences from others also in the home environment what with the advent of 'smart' everything these days.



This thread was automatically locked due to age.
Parents
  • Wait what!!! - #Default_Network_Policy allows all outbound traffic! - no wonder its all working lol! - DOH!

     

    I've only got 2 pc's on my internal network tbh - guessing it might be best to leave this as is and create additional rules to protect them 2 pc's? (rest are all media and mobile devices) - but then again this would mean someone could compromise one of the media devices/mobiles/consoles and manage to get out and misuse them?

     

    Wierd - I find it really strange that the default policy allows all outbound from LAN! - surely a standard firewall should be blocking ALL incoming and outgoing by default?

Reply
  • Wait what!!! - #Default_Network_Policy allows all outbound traffic! - no wonder its all working lol! - DOH!

     

    I've only got 2 pc's on my internal network tbh - guessing it might be best to leave this as is and create additional rules to protect them 2 pc's? (rest are all media and mobile devices) - but then again this would mean someone could compromise one of the media devices/mobiles/consoles and manage to get out and misuse them?

     

    Wierd - I find it really strange that the default policy allows all outbound from LAN! - surely a standard firewall should be blocking ALL incoming and outgoing by default?

Children
No Data