Hello,
I'd like to ask is it possible to create Rule that logs all IP addresses that tries port scanning and connections on closed ports on WAN port of Sophos XG?
This thread was automatically locked due to age.
Hello,
I'd like to ask is it possible to create Rule that logs all IP addresses that tries port scanning and connections on closed ports on WAN port of Sophos XG?
You can do this in Central Firewall Reporting with XDR: https://community.sophos.com/intercept-x-endpoint/i/data-lake/port-scan-detection-using-sophos-firewall-data-in-the-data-lake
__________________________________________________________________________________________________________________
Is this the only possible way? The firewall is not connected to Sophos Central and the policy of the company that uses the firewall does not allow it.
Is this the only possible way? The firewall is not connected to Sophos Central and the policy of the company that uses the firewall does not allow it.
So you are concerned about Port Scanning but are not using any cloud services? Because if you would be concerned about cloud security, you should close every port on your firewall as well, as this could potentially leak data as well.
__________________________________________________________________________________________________________________