Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Best Practice, Firewall, IPS, VPN ect.

Hi All,

 

We have a new XG + Sophos central/interceptX.

I have the firewall setup with a copy of LAN-WAN IPS with all but windows clients/servers removed, SSL decrypt+scan and yellow or above heartbeat policy setup.
Is this how we should go or does anyone else have any other strict but lenient configurations? also with the AD Auth we plan on using SSL VPN to allow remote users access via RDP, will this let them log into the VPN using AD account or do we still need to make a VPN user account? im trying to decide if its worth doing the AD sync and what benefits we would achieve from it.

 

As a IT consultant switching from trend to Sophos we want to have a seamless as possible approach and all of this is new to me and our team.

 

Thanks,
Anthony.



This thread was automatically locked due to age.
Parents
  • Anthony,

    Ips should match what you are trying to protect. You removed windows machine but you have rdp enabled for vpn so you still have windows machine.

    For the vpn, AD is right. You can force change passwords and lock users using gpo.

    I advice you to set avira as first AV engine because you have Sophos on endpoint.

    Regards

Reply
  • Anthony,

    Ips should match what you are trying to protect. You removed windows machine but you have rdp enabled for vpn so you still have windows machine.

    For the vpn, AD is right. You can force change passwords and lock users using gpo.

    I advice you to set avira as first AV engine because you have Sophos on endpoint.

    Regards

Children