Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall - How to add and specific firewall rule for an specific dhcp range?

Hi, im new with Sophos XG Firewall, mine is working greate, Im using a DHCP relay, so im getting my ips from my router (modem <--> router <--> sophos xg firewall <--> switch), and i have a default rule where im blocking proxies and apps that can make a tunel, but, in my router i have groups, like 192.168.110.10-20 = open social networks (given by mac reserve), but 192.168.111.1-254 = dhcp without youtube and social networks. I know (i think) how to make an app rule (I go to Applications/Application Filter i choose Add, then i clic on what i want to deny, and i have to set the "Action" Allow or Deny, i think in my case is "Deny"), but the part i have the question is, when im trying to add the second firewall rule, i dont know where i have to put my "DHCP Group", by the way, i just did the ip grup (Host and Services click on Add, set an Ip Range, input the information, click on Save. Host and Services, click on Ip Host Group at the top, and i just select the ip hos range)

 

Can anybody help me please? thanks.

 

When i add a new rule, i dont know where to make the referece for my ip range, the one i want to block :S

 

 

Thanks



This thread was automatically locked due to age.
Parents
  • The host range that you created under hosts and services > IP host can also be created directly within the firewall rule. 

    Create a new user/network firewall rule. Allow traffic as the screenshot below to customize your IP range

         

    Turn off match known users and apply webfiltering policy.

    I would try to control your content with webfilter first and use the default policy and deny not suitable for schools category. I usually get better results blocking or allowing categories through web filtering instead of application control. Customize the web filtering as needed as default school profile denies a lot more than just social networking.

     

     

    Hope this helps.

  • Thanks, im going to test that, just want more question, what about to make the rule at the bottom or at the top, whats the diference? i mean, it will affect to my other rules? for example, if in my general rule, im blocking proxies and other webfilter option, so in my second rule i have to do the same at least or what? thanks

Reply
  • Thanks, im going to test that, just want more question, what about to make the rule at the bottom or at the top, whats the diference? i mean, it will affect to my other rules? for example, if in my general rule, im blocking proxies and other webfilter option, so in my second rule i have to do the same at least or what? thanks

Children