This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Firewall Rule Best Practice

Hi All,

I just started testing Sophos XG as a VM in Hyper-V to make sure it will be suitable for our needs. As a Sophos UTMv9 user for a few years, I'm used to how that functioned and I noticed that, by default, Sophos UTM would block everything except what I specifically allowed. This meant setting up Definitions for services, Hosts, FQDN Hosts...etc to enable my network to talk to the outside world for all that was needed.

When I setup Sophos XG, I saw that I have the option to select a default "Allow All" except what's not allowed via any of the policies like adult content, inappropriate content for business, I can also block specific sites...etc. This options essentially allowed me to create a single firewall rule including IPS policy, traffic shaping and Web policy all within this single rule. I love this simplicity of setup but I'm not sure that this is what would be considered a best practice. For those of you here who've been working with Sophos XG for some time, what has been your standard approach? Do you setup with Deny All and then work to allow only those services that are required or do you Allow All except what you want blocked?

Call me paranoid, but I'm concerned that a single firewall rule, even if I've selected everything I want blocked, is the right way to go. Btw I've confirmed that the firewall rule is working as it is blocking access to resources I wanted blocked.

Would appreciate any insight you might have.



This thread was automatically locked due to age.
Parents
  • Example of rules you can create. For the DNS rule for example, I created a DNS-only DNS policy, as in that rule I will only allow the DNS service does not make sense to have other things in the IPS rule.
    For HTTP / HTTPS rule I used the standard IPS policy of XG LanToWan.

Reply
  • Example of rules you can create. For the DNS rule for example, I created a DNS-only DNS policy, as in that rule I will only allow the DNS service does not make sense to have other things in the IPS rule.
    For HTTP / HTTPS rule I used the standard IPS policy of XG LanToWan.

Children
No Data