Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to enforce local service ACL on Sophos xg v19.0.1 MR-1

Hi,

We are trying to implement local service ACL on LAN side but it's not working. After checking on community found multiple posts but none works. Below are the Drop all rule and ACL snaps:

Device Access:

Added another drop management portal (drop all) rule for testing purpose

ACL:

Tried to change source zone to LAN but that didn't solve the problem.



This thread was automatically locked due to age.
Parents Reply
  • Hi Abdullah,

    Apologies for reiterating your query.

    You want to turn off all LAN access going to your web Admin GUI except the "Ammar System IP" 

    I've replicated your configurations, and this is working on my side. Only the IP address (172.16.16.17 and .100 ) defined on my Source Network/Host* are allowed. 

    Once I removed the IP of .100, this one got blocked.

    Would it be possible to retry the IPs that aren’t included on your "Ammar System IP" and send a screenshot of the logs

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Children