Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS Firewall - Application Sync - SSL-Inspection - Rules?

Hello Sophos Community,

I got a Question about designing specific Rules for Applications that are very untransparent how they handle SSL Fingerprinting.

Example:

From: LAN Zone - From: Specific Host - With Application A (Application RULE 1) - To: WAN Zone - To: Specific Host - With: Protocol A-B-C
Disable DPI and Proxy SSL-Inspection

Everything else 

Example:

From: LAN Zone - From: Any Host - With diverse set of Applications (Application RULE 2) - To: WAN Zone - To: Any - With: Protocol A-B-C 

The Applications are Synced with Intercept X Adv. with XDR to the Appliance and there are specific Application Rules -> 

Example:
Rule 1 - Has an allow for the Application that needs NO SSL-Inspection

Rule 2 - Has all the other Applications that are Sanctioned and specified with SSL-Inspection

The reason is the following:

The Application also connects with IP-Addresses that change over time plus it does not like to be SSL-Inspected. I tried with Rules Exclusions for the SSL-Inspection but since the IP-Address Changes over-time it is a very daunting task...

Best regards

Val.



This thread was automatically locked due to age.
Parents
  • Hello to all,

    am I understanding the meaning about Application Control in the Sophos XGS wrong?

    I thought if I setup a rule that should allow a specific Application discovered by Intercept X Adv. and with Application Sync (Sophos Central).

    It is possible to build rules based simply by allowing a set of applications - Simply put Allow Application on a Firewall Rule and the ports do not matter anymore since it should filter by that set of applications or is there another meaning behind it? ;)

    Many thanks for any feedback

    Val.

Reply
  • Hello to all,

    am I understanding the meaning about Application Control in the Sophos XGS wrong?

    I thought if I setup a rule that should allow a specific Application discovered by Intercept X Adv. and with Application Sync (Sophos Central).

    It is possible to build rules based simply by allowing a set of applications - Simply put Allow Application on a Firewall Rule and the ports do not matter anymore since it should filter by that set of applications or is there another meaning behind it? ;)

    Many thanks for any feedback

    Val.

Children
No Data