Hallo everyone,
I’m planning on deploying a Sophos XG (Home Edition) on my infrastructure at home. As I’ll plan to get some new hardware for that I would like to double check my plan; hopefully with your help and advice.
Here’s a brief overview of my current network situation:
- Switch: HP 1810-24g (not the current version but from somewhen 2008)
- NAS: Synology DS-1511+
- Clients:
- 3-4 Windows Client
- home-typical clients as streaming clients, game consoles, TV, printer, etc.
- VMWare ESXi (mostely a sandbox; 4 NICs)
- a few internal used VMs for ActiveDirectory, DNS, etc.
- 2 Linux server for external Access
- Router: Asus RT-AC68U
- Connection: 400/20 Mbit with 5 static public IP addresses
The plan is to switch the Asus Router for a Sophos XG and an additional WiFi access point and divide the whole network into 3 segments: LAN, DMZ & WAN. (classical)
The DMZ would contain the 2 servers for external access and the LAN segment everything else. (I also had the thought to use 2 other segment: WiFi & management network. But I’ll care about that later ... think big, start small.)
So first question: Hardware for the Sophos XG
I found an interesting product on amazon: Firewall Barebone
Specs: Core i3-7100U or Celeron 3865U, 8GB Ram (yes, only 6 are addressable with the HomeEdition), H67 chipset, 6x Intel 82583V, 128GB SSD)
Does the Celeron do the Job for the 400/20 WAN connection (Firewall, IDS, WebFiltering) + some low bandwidth connections between LAN and DMZ or should I better stick to the i3 version?
Second question: Network-implementation
The idea is, so separate the segments via VLAN-tagging. So the switch ports of the ESXi (which runs the DMZ-hosts) as well as the Sophos XG will get a dedicated VLAN tag for the DMZ-Traffic. Within ESXi I can define a NIC that tags the hosts traffic. The ports on the switch which are used by ESXi and Sophos will be assigned to the corresponding vlan in addition to “no vlan”.
Is this approach constructive?
Are there any points to consider from a security point of view?
Third Question: WiFi Access Point
I love the idea of being able to manage my WiFi from within the Sophos XG. Unfortunately the Sophos-Devices supporting 802.11ac standard are quite pricey (300€ +). I would be fine spending ~130€ on a AP 15, but … no 802.11ac.
Which other WiFi-products can you suggest? I heard Ubiquity products are very good?
Is Sophos planning to release a 802.11ac capable AP 15?
Thanks for reading the long post and your advice
Regards
Chris
This thread was automatically locked due to age.