Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mirror VPN traffic terminated into Sophos XG running 17.5.12 MR-12

I am new to Sophos so I am looking for some help.  My customer came to me and he would like to mirror all the VPN traffic that terminates through his Sophos XG.  The reason is that the traffic terminates and then exits to a device where mirroring of the traffic is not possible (it is owned by the carrier).

Is there a way to mirror (SPAN) traffic terminated from VPN connections to an interface in an Sophos XG running 17.5.12 MR-12?



This thread was automatically locked due to age.
Parents Reply Children
  • You can glean from which address the client is using, what mac-address, what is the public address, which service in Azure they are going to, how much traffic is exchanged in each direction, which ciphers are used, which hash.  You get to look at the certificates for their information and validity.  There is a lot of metadata there...you don't need to see the payload.  Now that that information with the other logs you have from the EDR, the servers and any other solutions and you have a clear, auditable view of what is going on in your environment.