Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Will a Web Filtering Profile (limiting time of Social Networking) work on the DMZ as it does on the LAN?

Splitting a facility (one location, two buildings, one SG135w) across LAN and DMZ.

More secure traffic on the DMZ.

Have working a Social Media filter on the LAN.

Will this same style filter work on the DMZ as it does not seem to have affect on the DMZ at this time (cloned the process to point to DMZ instead of LAN).

CS



This thread was automatically locked due to age.
Parents
  • Chasster123,

    Policy rule can be applied on any zone and traffic is filtered. So you can filter social media from DMZ to WAN. Also for security reason, hosts in DMZ should have access to only website used to update servers content and not used for surfing on internet.

  • Understand.

    Likely I need to address the two-building split differently.

    Perhaps put building 1 on the LAN and building 2 on another ETH port (maybe 4).

    I think in that mode (not using the purpose of the DMZ) access to the Domain server will be OK even with the LAN and ETH4 being on separate subnets.

    cs

  • If you want to have them in different subnet, it is a good solution. The alternative is to connect both building using different ethernet ports and create a bridge. The bridge then belogs to zone LAN.

    For security prospective, use VLAN or different subnet is the best way.

Reply
  • If you want to have them in different subnet, it is a good solution. The alternative is to connect both building using different ethernet ports and create a bridge. The bridge then belogs to zone LAN.

    For security prospective, use VLAN or different subnet is the best way.

Children