Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pls help me understanding the XG v18 ACL matrix

Hi everyone,

This is the ACL matrix of Sophos XG v18 firewall system.

Would you please explain to me in more details about the rows and columns of this ? I would like to know more in partiular about the SSL VPN column :

  1. If I uncheck the SSL VPN box at WAN row, can I still access the XG system remotely via SSL VPN ?
  2. Why is the SSL VPN box at VPN row disabled ? I can not check it by any means.

Thank you very much in advance.



This thread was automatically locked due to age.
Parents
  • Just 2 more questions. Despite having unchecked all services available on the WAN row, why are there still signals from strange foreign IP addresses trying to contact my XG Firewall at different port numbers, to which it has denied ?

    Also, in the log viewer, how may I view the traffic connections that have been allowed by the firewall system ?

    Thank you in advance.

Reply
  • Just 2 more questions. Despite having unchecked all services available on the WAN row, why are there still signals from strange foreign IP addresses trying to contact my XG Firewall at different port numbers, to which it has denied ?

    Also, in the log viewer, how may I view the traffic connections that have been allowed by the firewall system ?

    Thank you in advance.

Children
  • Hi : The Packets will reach XG as IP is publicly routable but the intended destination service is not on or not configured ON XG due to that firewall will drop the same with denied action with invalid traffic. If you do not want traffic should not reach to XG then on (next hop device) possible ISP router on your premise - you may block those destination and that will not forward those specific destination traffic on XG

    To see allow traffic/connection, you may apply the filter with IP and with the allowed conditions. 

    Example:

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?