Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

connection with bad ip address

hi,

if i have sophos XGS or XG and from lan my users start making connection with bad reputed ip address. then can firewall block it??? ATP is same or it is different?

can SOPHOS XG/ XGS also consult some IOC Feed ???



This thread was automatically locked due to age.
Parents
  • Hello ,

    Thank you for reaching out to the community, may I know what is the ATP settings configured it is just "Log traffic" OR " Log and Drop" 
    And LAN to WAN scenarios if you have created a stop web/app policies then based on the bad ip reputation category blocked in web policy can prevent !! 
    And by default FW will drop/reject traffic which is not allowed explicitly like for an instance WAN to LAN !! 
     

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hello ,

    Thank you for reaching out to the community, may I know what is the ATP settings configured it is just "Log traffic" OR " Log and Drop" 
    And LAN to WAN scenarios if you have created a stop web/app policies then based on the bad ip reputation category blocked in web policy can prevent !! 
    And by default FW will drop/reject traffic which is not allowed explicitly like for an instance WAN to LAN !! 
     

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Children