Im getting heartbeat denied events in my XG logs, what do i need to open in a rule for this?
This thread was automatically locked due to age.
Im getting heartbeat denied events in my XG logs, what do i need to open in a rule for this?
For all clients or only for certain?
Can you check the heartbeatd.log?
Which IP is it?
https://community.sophos.com/kb/en-us/132211
Can you show us your Firewall ID 1?
First of all, XG decides if a Rule matches on following criteria:
Source IP*
Destination IP
Service
*Source IP can be replaced with a Username.
All other "Features" like Sync-Sec Heartbeat are additional action and will be applied, if the rule is applied.
The XG uses a first match system. So basically, if it finds a matching rule based on the criteria mentioned above, this rule will be applied.
You cannot "clone" a rule without heartbeat. It will not be applied.
Heartbeat is not a criteria to filter traffic. It will be applied no matter what you select.
All IPs used by XG: https://community.sophos.com/kb/en-us/126576
First of all, XG decides if a Rule matches on following criteria:
Source IP*
Destination IP
Service
*Source IP can be replaced with a Username.
All other "Features" like Sync-Sec Heartbeat are additional action and will be applied, if the rule is applied.
The XG uses a first match system. So basically, if it finds a matching rule based on the criteria mentioned above, this rule will be applied.
You cannot "clone" a rule without heartbeat. It will not be applied.
Heartbeat is not a criteria to filter traffic. It will be applied no matter what you select.
All IPs used by XG: https://community.sophos.com/kb/en-us/126576
Thanks for that link, its just what i need.