Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SD-Wan to communicate with Sophos central / live protection

i have XG firewalls located in china and sometimes the latency of some links to sophos getting to slow so i dont get a resonse in time for example for live protetcionn

right now im trying to setup a SD WAN for all sophos services, but that it work well i would need to know which IP's i should monitor that SD-wan route can decide which is the best gateway.

would it be possible to get an IP list which i should probe for which service?
also at the moment i chose these destination networks.

It would be great if Sophos would offer default SD-Wan profiles in the next release to sophos services (cloud) to always communicate with sophos trough the fastest possible link as conectivity to sophos is super critical if you use Sophos firewal, sophos endpoint protection and so on.




This thread was automatically locked due to age.
Parents
  • Hello  ,

    Thank you for reaching out to the community, the following link will guide you to choose between: "Traditional Settings For Primary and Backup Gateway:" and "New SD-WAN Profile Settings From v19 Onwards:" - Sophos Firewall v19: How to Choose The Gateway For A Firewall Rule 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • i know how to setup an SD wan, the question is what is the best setting for an SD Wan to route traffic to sophos.
    1: Which destinations i should route?
    2: which IP i should probe to check the gateway connection quality to Sophos?

  • Hey  ,

    That strictly depends on your requirement, we have given two methods. with the New SD-WAN you can check the link status and the historical performance, enables performance-based SLA link selection and routing based on real-time packet loss, jitter and latency with zero-impact rerouting of application traffic when transitioning between links. Performance monitoring criteria includes jitter, latency and packet loss and can utilize multiple probe targets for PING and TCP probes. SD-WAN profiles automatically select the best link based on performance or according to your custom SLA policies that define specific values for maximum acceptable jitter, latency, or packet loss before re-routing over a better performing link.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hey  ,

    That strictly depends on your requirement, we have given two methods. with the New SD-WAN you can check the link status and the historical performance, enables performance-based SLA link selection and routing based on real-time packet loss, jitter and latency with zero-impact rerouting of application traffic when transitioning between links. Performance monitoring criteria includes jitter, latency and packet loss and can utilize multiple probe targets for PING and TCP probes. SD-WAN profiles automatically select the best link based on performance or according to your custom SLA policies that define specific values for maximum acceptable jitter, latency, or packet loss before re-routing over a better performing link.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?