This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Resource for automating XG tasks that SFM does not give you

Hi all - I'm looking to build a cache of resources and scripts to automate some tasks that the Sophos Firewall Manager (and I assume the Central Firewall Manager) cannot give us.  Namely, we should be able to automate a few tasks:

  • systems services status and restart capability: for example, if awarrenthttp goes down, we should be able to attempt a restart without having to sign into the firewall directly, and grab a status list to send off to a monitor somewhere
  • system reboot
  • apply pattern updates (I just do not want to update AP firmware at 2pm in the middle of the day, and I only work M-F 9-5, also why would I do it by logging into the device at 2am? - I want to schedule this).

Currently, for system reboot, I'm trying to use an ACL to a secure Linux system I set up so I can issue a command to it, and it will login to the remote firewall and perform the reboot for me at the appropriate time.  I'm looking to add things like service restarts and pattern updates, but I'm not sure how to do the pattern updates via CLI.  Part of the issue is that the supported CLI doesn't let you do most of what you'd need to do and the advanced, unsupported CLI isn't documented anywhere I can find.

Do these resources already exist in a place that makes sense for me to contribute?

Often when I approach support about feature requests, I'm told to just use the feature request portion of the community site, where ideas go to die.  So I feel as if we should take some initiative into our own hands here.



This thread was automatically locked due to age.