Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAF Restrict traffic from WAN

Hello There.

Are there any information when SOPHOS will improve WAF option on its iwn devices?

Why we dont have such basic option to limit source traffic from WAN only for specific country? 

So far we can  only do IPs..



This thread was automatically locked due to age.
Parents Reply Children
  • Can you explain, why there is rule for "From WAN to WAN"? what is the logic behing it? is it some kind of loopback or esle?

    I have hade already specific rule but with small exception - as destination i have  'ANY'. <--- is it bad?

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • This should not be a Problem. Reason is, you want to drop the traffic, if the firewall rule not applied, it will be dropped, if the rule does apply, it will be dropped. The outcome is the same. Only logging would not be there, if the firewall does not apply. So if you see drops in your logviewer by your Blackhole Rule, you are fine. 

    __________________________________________________________________________________________________________________

  • ok then, thx for help its working like a charm ^^  Slight smile

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • Can you also explain why after setup BlackHole DNAT rule i cant see "Web server protection" logs anymore? I guess its cuz it catches in "block country" FW rule where NAS is linked.?

    EDIT:
    So actually there was no need to create BlackHole NAT rules cuz it was only enought to just limit source in exristing DNAT WAF policy. But you loose WAF logs for that particular traffic as it will not catch into waf policy... pity

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb