Does Sophos XG do IP source address reputation scanning for all inbound traffic irrespective of port/proto?
I ask because my net is like this inet NAT router<>sophos XG in bridgemode <>cujo in bridge mode<>rest of network
And the cujo is blocking MANY inbound attempts as probing my NAT'd ports based on IP reputation, I would expect the cujo to see nothing and XG to block these (given the price differential).
I see in docs that XD does IP reputation scanning for SMTP/S - not sure if it is for anything else.
This is my inbound rule, incase someone can advise if i forgot to turn something on.
Rule
Accept any service going to "LAN" zone, when in "WAN" zone, and coming from any network, scan for malware then check with Sandstorm and log connections, then apply IPS policies
Source & Schedule
Source Networks and Devices : Any
During Scheduled Time : All the Time
Destination & Services
Destination Networks : Any
Services : Any
This thread was automatically locked due to age.