This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SNI Support

Is SNI supported by XG Firewall?   I have multiple SSL certs for multiple domains and one IP and I would like to be able to route traffic to virtual web servers based on this host name inspection. Web servers like Apache, nginx, and IIS as well as every modern browser support it. I would like to manage this and SSL termination on Sophos rather than something downstream.

 



This thread was automatically locked due to age.
Parents Reply Children
  • I realise this is an old thread, but it seems to be causing confusion and I want to set the record straight.

     

    SNI is supported by XG Firewall for Web Server protection.

     

    When you create a Business Application firewall rule using the Web Server Protection template, and select HTTPS, you can specify the certificate to use and the hostnames that apply for that rule.

    If you create multiple of these rules using the same port and IP address, but with different certificates and hostnames, it will select the correct rule based on the SNI in the TLS handshake that is sent by the end-user's browser.

     

    Note that this approach can't work for port forwarding or DNAT rules, where the WAF is not used and TCP packets are just forwarded directly to the server.