Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: Configure web exceptions for other vendors, not just Office (Microsoft 365)...

Hi,

After having all kinds of problems with various Microsoft 365 systems, I finally found the KB article KB-000038173 "Sophos Firewall: Configure web exceptions for Office 365". After setting up these exception templates and activating them everything appears to be working much better now. What an awesome thing that article and associated templates is! Saved me, and no doubt hundreds of other pros, admins and partners, hours of beating our heads against a wall and will continue to do so for a good while.

Does anybody know if Sophos have published any other similar exception templates, for other vendors. This list would include:

1. Sophos - Yes, their out-of-the-box "protect my network" rule blocks access to even their own systems/services (I can't even log into my Sophos account!)

2. Google Suite.

3. AWS?

4. <Insert your ubiquitous vendor of choice here>.

Cheers,

David.



This thread was automatically locked due to age.
  • Do you use DPI or the legacy proxy? 

  • That's a fair question. This is a brand new device, running the out of the box configuration. The setup wizard asked me if I wanted the device to scan and protect my HTTP/S traffic, to which I responded, yes and it created a default rule. I haven't looked into it to see if it's using legacy or DPI, yet. One would hope that it would prefer DPI over creating an OOB legacy proxy but I'll take a look and confirm back.

  • DPI engine support a "Managed TLS exception List". You find this list here: Web - URL List

    The issue with vendor exception is always: Those exception needs to be re validated all the time. And it needs to be known to be a trusted source and other factors. Hence Sophos is not simply putting "everything" in there, which could be an issue.