Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Thinking of trying Sophos XG Home. Some questions.

Hi everyone. I have a couple questions. I currently run pfSense in my home network/homelab. I was thinking of maybe trying out Sophos XG. I have no problem with my pfSense it runs great but when I was checking out Sophos it seemed to be more similar to what I work with at work which is Palo Alto. For this reason, I was thinking it may better for my learning to have a similar firewall software running in the house for learning purposes. I have one concern though and a couple questions.

My concern is related to hardware. The hardware I have right now running pfSe nse is a SuperMicro SYS-5018A-FTN4 1U Server barebone. The CPU in it is an Intel Atom C2758 2.4Ghz 8-Core. I have 16 GB DDR3 RAM and a 120GB SSD in it. I read that Sophos XG Home has hardware limitations which are 4cores and 6GB RAM. Is there no way to remove these? By that I don’t mean working around them but is there any paid subscription (that isn’t ridiculously high enterprise pricing) that will remove the hardware limitations? I am really interested in trying Sophos XG but r eally don’t like that it is going to neuter my hardware killing over half the power of my box.

The questions I had were as follows: https://omegle.onl/

 How do vlans work with Sophos XG? Right now, I have one NIC for WAN, one for LAN, and the other two in a LAGG and all my VLANS use the LAGG for the VLAN interfaces. Is it possible to set Sophos up in a similar way? Or is there a better way to set this up that I should be doing?

Any recommendations/guides for initially setting up rules for a home network? I have watched a ton of videos on setting up rules, vpn, web/app/intrusion/etc. policies, and other parts of Sophos XG. I will be turning on many of these thin https://vshare.onl/gs but will not be blocking things like games and other stuff that you would normally block in enterprise but not in a home environment.

Thank you for your help and time.



This thread was automatically locked due to age.
Parents
  • Hello,

    I read that Sophos XG Home has hardware limitations which are 4cores and 6GB RAM. Is there no way to remove these? By that I don’t mean working around them but is there any paid subscription

    There's no legal (free) way to remove this limitations without purposely bypassing It.

    How do vlans work with Sophos XG? Right now, I have one NIC for WAN, one for LAN, and the other two in a LAGG and all my VLANS use the LAGG for the VLAN interfaces. Is it possible to set Sophos up in a similar way? Or is there a better way to set this up that I should be doing?

    Yes, VLAN's work as expected.

    Any recommendations/guides for initially setting up rules for a home network?

    Delete the default Firewall and NAT Rules that are available after the installation, and create your own from scratch.

    You should also create a new "Drop" Rule at the bottom of the list with all available zones for both destination and source with logging enabled. The default Drop policy doesn't have any logging.

    One reminder, it's not possible to use Zones on the NAT Rules.

    what I work with at work which is Palo Alto

    A reminder, Sophos Firewall is compeltely different from Palo Alto in the FW Rules creation.

    While with Palo Alto you work directly with L7 aware policies, by being able to work directly with applications; On Sophos you will create policies based on L3-L4, with IP's and Ports, then apply "App-ID" and URL filtering.

Reply
  • Hello,

    I read that Sophos XG Home has hardware limitations which are 4cores and 6GB RAM. Is there no way to remove these? By that I don’t mean working around them but is there any paid subscription

    There's no legal (free) way to remove this limitations without purposely bypassing It.

    How do vlans work with Sophos XG? Right now, I have one NIC for WAN, one for LAN, and the other two in a LAGG and all my VLANS use the LAGG for the VLAN interfaces. Is it possible to set Sophos up in a similar way? Or is there a better way to set this up that I should be doing?

    Yes, VLAN's work as expected.

    Any recommendations/guides for initially setting up rules for a home network?

    Delete the default Firewall and NAT Rules that are available after the installation, and create your own from scratch.

    You should also create a new "Drop" Rule at the bottom of the list with all available zones for both destination and source with logging enabled. The default Drop policy doesn't have any logging.

    One reminder, it's not possible to use Zones on the NAT Rules.

    what I work with at work which is Palo Alto

    A reminder, Sophos Firewall is compeltely different from Palo Alto in the FW Rules creation.

    While with Palo Alto you work directly with L7 aware policies, by being able to work directly with applications; On Sophos you will create policies based on L3-L4, with IP's and Ports, then apply "App-ID" and URL filtering.

Children
No Data