I'm brand new to Sophos. Have a basic understanding of firewall rules but want to confirm the correct setup.
Have an XG 115 for a small business. Very simple network setup/needs.
Right now I just have one rule which is LAN to WAN, any host > any host, any service. The only reason I can think of to block any services for LAN to WAN would be if some sort of bot got installed on the machines, but I would expect those are going to use pretty standard ports to communicate out anyway (80, 443, etc)
So is there really any significant benefit to not use 'all services' for LAN to WAN (again this is a 9-user small business).
All the users need access to is the basics:
Web (http/https)
Outlook access to Cloud Email Exchange Server (IMAP / POP) I assume I don't need SMTP open since the Cloud Exchange server is sending/receiving the email.
What I am concerned about is WAN to LAN services. I don't want anyone being able to try to hack internal machines or attempt to connect to Windows File Shares. There's no WAN to LAN policy setup. Am I protected or do I need to add one?
I'm also using LogMeIn but that uses port 443. Do I need to setup a WAN to LAN polciy to allow LogMeIn access?
This thread was automatically locked due to age.