Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG 18.0.6 Logging of NAT Rules and DNS activity

Running XG 18.0.6 on my own hardware.

Short version: How do you log activity of:

a) DNAT rule which diverts DNS to the Sophos LAN Port

b) The DNS service itself

I can do some packet capture, but the logging tool seems to ignore a DNAT rule terminating on the Sophos itself.

Longer version:

DNS is provided by a Windows Server for most devices, but I have some devices that will not use this. To allow them to function I have rules to pass this traffic outwards, and a default MASQ which applies.

One of such devices uses a Google address which changes IP very frequently, and so would be best dealt with by using a FQDN identifier in the filter rule, which necessitates the use of Sophos DNS. I am having trouble identifying whether everything is working properly.

I performed the following steps:

  1. Created a rule (at top) to capture all of the outbound DNS requests from the device
  2. Checked that this captures everything, and that it then passed through the default MASQ NAT rule.
  3. Enable the DNS facility
  4. Enable the device to access DNS via an exception rule under “Device Access”
  5. Created a new NAT rule (at top) which should match (not sure about “Outbound Interface”), which should take the external DNS requests and send them to the LAN IP Address of the Sophos machine (which is Port1)
  6. The Usage counter ticks up for the new NAT Rule showing that something is happening, but it is difficult to tell what!
  7. Logging fails to show any activity under “NAT Rule = 2“
  8. It also fails to show anything using the source IP and destination port
  9. Packet capture show something:
  10. Is there a way to check whether the DNS feature is working? A cache dump? A log file?

The arrangement seems to be working, butif something fails, it will be hard to debug - I don't seem to be able to track the packets as I would normally.

Any suggestions/corrections welcome.

Regards,
Paul McGinnie



This thread was automatically locked due to age.
Parents
  • Hi,

    you appear to be doing the DNS the hard way, why not set the DNS in the DHCP server and use the IP address of the gateway as the DNS? The google DNS does not change address. You could use a static IP, address for the device.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks - i know that it might be easier to reconfigure the whole thing to use Sophos as the DNS server generally. However, the Windows Server DNS does seem more functional than the sophos version, so I remain to be convinced before planning to move over lock stock and barrel to Sophos DNS.

    Until then, the problem remains - is there any way to actually see the activity of the DNS on the Sophos - inbound packets don't appear in the standard logging tool, and there is no cache visbility that I can find. Without something like these it is difficult to check for problems!

    Regards,

        Paul

  • I wasn’t commenting on the use of your internal server, I agree way more functional than the xg. I was commenting on your Nat for the internal device to talk to the external XG as a dns.

    if you have logging enabled on the firewall rule, the traffic should show in logviewer and include the Nat rule, but this was added in a v18.5x update.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • I wasn’t commenting on the use of your internal server, I agree way more functional than the xg. I was commenting on your Nat for the internal device to talk to the external XG as a dns.

    if you have logging enabled on the firewall rule, the traffic should show in logviewer and include the Nat rule, but this was added in a v18.5x update.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?