Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pls help me understanding the XG v18 ACL matrix

Hi everyone,

This is the ACL matrix of Sophos XG v18 firewall system.

Would you please explain to me in more details about the rows and columns of this ? I would like to know more in partiular about the SSL VPN column :

  1. If I uncheck the SSL VPN box at WAN row, can I still access the XG system remotely via SSL VPN ?
  2. Why is the SSL VPN box at VPN row disabled ? I can not check it by any means.

Thank you very much in advance.



This thread was automatically locked due to age.
Parents
  • If SSLVPN and User Portal is on the same Service Port (443 or 8443) it will share the service. Therefore ACL will not block it. ACL is based on service port. So you can block 443 in this matrix, but it will not block it, if SSLVPN is enabled and User Portal is disabled. If you do not want this behavior, service port change could be a approach. 

    SSLVPN cannot be blocked on a virtual zone like VPN. So VPN is everything, IPsec or SSLVPN is active. You cannot disable SSLVPN in a SSLVPN Tunnel. That would not make sense. 

    __________________________________________________________________________________________________________________

Reply
  • If SSLVPN and User Portal is on the same Service Port (443 or 8443) it will share the service. Therefore ACL will not block it. ACL is based on service port. So you can block 443 in this matrix, but it will not block it, if SSLVPN is enabled and User Portal is disabled. If you do not want this behavior, service port change could be a approach. 

    SSLVPN cannot be blocked on a virtual zone like VPN. So VPN is everything, IPsec or SSLVPN is active. You cannot disable SSLVPN in a SSLVPN Tunnel. That would not make sense. 

    __________________________________________________________________________________________________________________

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?