Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Allow only certain traffic to exit Windows in a XG environment

Running a Windows Server farm on VMware in a XG environment . We want only certain allowed traffic from the Windows Server to exit the network. 

( Eg in a Windows 2019 SQL server, block all outgoing connections to office.com, SharePoint, www and allow only 1433 port connections in the LAN something like this) We have created a full list of all outgoing traffic from the servers and require only to allow certain services to communicate outside. We also run Sophos Central Intercept X advanced on all workstations & servers.  Can you suggest best practices and how this can be achieved. Many thanks 



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    I would recommend you to create:

    1. Set a static IP for the Server

    2. Create a "Clientless users"  entry for the server

    3. Create a Firewall Rule with Match Known users and select the Clientless user you just created

    4. Configure the Firewall using the Destination networks* add the IPs/FQDN you want to allow 

    5. Remote the "Any" from the Services, and only set the allowed outbound ports usually only 443/80 and 53 (if the Firewall  isn’t the DNS resolver)

    6. Source Network and Device, enter the IP of the Server

    If you have Intercept X, then enable Sync Sec in the Firewall Rule

    This would be my recommendation, but I would suggest you check with your Sales Engineer if you’re looking for best practices.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello there,

    Thank you for contacting the Sophos Community.

    I would recommend you to create:

    1. Set a static IP for the Server

    2. Create a "Clientless users"  entry for the server

    3. Create a Firewall Rule with Match Known users and select the Clientless user you just created

    4. Configure the Firewall using the Destination networks* add the IPs/FQDN you want to allow 

    5. Remote the "Any" from the Services, and only set the allowed outbound ports usually only 443/80 and 53 (if the Firewall  isn’t the DNS resolver)

    6. Source Network and Device, enter the IP of the Server

    If you have Intercept X, then enable Sync Sec in the Firewall Rule

    This would be my recommendation, but I would suggest you check with your Sales Engineer if you’re looking for best practices.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children
No Data