Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Incorrect SSL Certificate shown when accessing internal Server from WAN on port 443

I have a DNAT in place from WAN port to internal server on port 443 (HTTPS) for accessing to users workfolders. When you connect to external URL it gives out the sophos XGS 2300 appliance certificate instead of the ssl certificate installed on the server  so it fails to connect.

How do you let client see the real server SSL certificate and not the Sophos appliance certificate.

I have tried adding a firewall rule at the top that has no web policy and no https decryption.

I am moving from a Watchguard appliance to a Sophos XGS 2300, it worked fine on the watchguard



This thread was automatically locked due to age.
Parents
  • I would highly recommend not to still use DNAT for services in the year 2022. It will expose a service to WAN without any restriction, opening a much higher attack surface. 

    Think about ZTNA/VPN applications. 

    __________________________________________________________________________________________________________________

Reply
  • I would highly recommend not to still use DNAT for services in the year 2022. It will expose a service to WAN without any restriction, opening a much higher attack surface. 

    Think about ZTNA/VPN applications. 

    __________________________________________________________________________________________________________________

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?