Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNS in an emergency rule setup

Good day everyone!

I am currently implementing an emergency firewall ruleset, which looks like this:

- Allow all communications towards sophos central (for Live Response etc. to work)

- Allow all communications coming from the physical Management Port of the firewall

- Drop everything else

In case of an emergency (ransomware outbreak or whatever) the plan would be to enable this set of rules to prevent any potentially malicious communication from happening, while still allowing the MDR team to get to work.

On top of that I was considering adding an ACL exception drop rule, to further restrict communications towards services of the firewall. Sadly these rules cannot be added and kept disabled, like it is possible with firewall rules. At least to my knowledge?

Another thing I haven't quite found a solution for: How can I prevent all DNS resolution (firewall is the main source of DNS internally) except those towards specific domains (Central...)? I was thinking this could maybe be implemented using a custom IPS rule?

Has anyone ever done anything like this and can share some ideas?

Thanks in advance!

Regards,

Ben



This thread was automatically locked due to age.
  • Hello there,

    Thank you for contacting the Sophos Community.

    The ACL rules can only be set to Drop and or Accept.

    For the question related to DNS, you can disable DNS from the Local ACL for the specific zones, create a drop DNS Firewall rule as you mentioned, or create an FQDN rule for the central domains as allow for specific computer(s).

    Regards,