Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNS request for internal resources

Hello everyone,
I need to get some SSL VPN users to a server with a local URL ("">">http://myurl.local").
The steps I followed:
1) My Xgs2300 has the two domain controllers and google's dns as its dns server
2) Configured a VPN policy only for these users (use as default gateway off)
3) Configured a DNS host entry
4) In my SSL VPN GLOBAL setting I entered the ip of the LAN port of my firewall as primary DNS (I would like to avoid dns queries towards the two domain controllers)
Everything works but by doing so the VPN users can also reach the "4444" port of the Firewall webadmin.
I would like to block the accesses of these users only to the DNS service of the LAN port but I can't.

Any suggestion?

Thank you



This thread was automatically locked due to age.
Parents
  • Hello,

    all you got to do is disable „HTTPS“ under Admin services at Administration/Device access . There is a matrix where you uncheck that service for the VPN zone..

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Hello Philipp, thank you for response.

    I know but I can't disable HTTPS because I need to gain access to webadmin for me.

    Best regards

    Galileo

  • Hello,

    I would use a jumphost for this purpose.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data