This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to make security heartbeat work?

Dear Sir,
I have apply a trial Sophos Central for 30 days,
and make it to integrate with XG home version.

Both the Central & XG get sync each other,
but the XG's Security Heartbeat always show 0.

How to make XG's security Heartbeat work?

Sophos Central's license as below.

XG's security heartbeat enabled.

Sophos Central get XG appliance.

Sophos Central has user & computer on it.



But the security heartbeat is always 0?

If I enable security heartbeat on LAN to WAN rule,
the user would be blocked, since it's status won't sync to XG.

Anybody know what's wrong with the setting?



This thread was automatically locked due to age.
Parents
  • HI ShunzeLee, 

    Let me check and get back to you . 

    Thanks 

    Aditya Patel 

  • I have changed the XG from Home Virtual version to real appliacne,

    but got the same result...

      

    Maybe Sophos Central 30 days trial version doesn't support heartbeat?

  • Hi Shunzelee

    The reason this is not working is because the heartbeat (connection to endpoint is located on Sophos Central)- You'll need a seperate firewall rule to allow communication to Sophos Central servers. 

    After this point, you should be able to see the number increase.

    Below are the FQDNs if you need to create a rule

    sophos.com
    mojave.net
    sophosupd.com
    sophosupd.net
    sophosxl.net
     
    Hope that helps.
  • No rules are needed to allow communication to Sophos Central. Communication is allowed by default from XG.

    You can use a tcpdump to check the communication with Sophos URL and post it!

  • Hello Luk

    I checked this and I unfortunately I will have to disagree with you on this. 

    When I disabled the firewall rule for my machine, the ping stopped. 

    when enabled, ping worked. 

    Screen shot below:

     

    Once again, what I meant above is to allow communication from endpoints to Sophos URLs, I understand that Firewall to Sophos URLs will always work. 

    Hope this helps.

  • Thanks Varun.

    I tested heartbeat on v15 and it was working correctly.

    Something changed?

    This can dangerous! If an admin block internet to some devices to internet, those devices with hb will stop to work. Admins prefer to set deny rules on top.

    I think that hb should work as hidden or be controlled by device access.

    I was quite sure that no policy rules were needed on v16.

    This can be very very dangerous and confuse admins that do not know that!

    Another feature request?

    Thanks Varun!

  • Varun,

    so if this is the behaviour, al already LAN to WAN Policy rule where traffic HTTP/HTTPS is allowed, this should be enough for Sophos HB devices to communicate with Sophos Central.

Reply Children
No Data