This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Time-Based WAF-Rule possible on XG Firewall ?

Hi Folks !

I have an interesting question due to a request from one of my customers. He asks me, whether there is a possibility to limit Access to Outlook-Anywhere outside of normal Work-Hours.

Background of the question is, that the CEO want prevent the Danger of a "Burnout-Syndrome" on his employees. He discovered, that many of his personnel receive and write mails via mobile devices outside of normal Office-Work-Hours, so he is wiling to do all necessary to stop the workaholics from taking over (Yeah i know, some Directors would be happy if they had such involved employees)...

But Ok, let's give it a try. On the Company-Side, there is located a Sophos XG115 with Firmware "SFOS 16.05.6 MR-6" installed.

So my first intention was (nothing easier than that) to set up a firewall rule on the top, named it "Burnout_Prevention_Rule" and made the setting to block all requests from WAN to the Public-Interface that is hosting the Outlook-Anywhere-Requests and Internal-Address of the Exchange Server on Port 443.

Sadly to my astonishment, the rule completely will be ignored, even when the WAF-Rule for Exchange is on the Bottom of the Rule-List. It doesn't matter which kind of settings i made, all options will be ignored and it seems that Business-Rules always have higher priorities than Network-Rules. 
In the WAF-Rule itself i didn't found any possibilities for time-based access-settings.

 

Does anybody know if there is a way to limit WAF-Rules in such way ? or what we can do otherwise to solve that problem (instead of taking power off the firewall at the Offtime-Workhours *joking*).

Thanks and Best Regards :-)
Josef



This thread was automatically locked due to age.
  • Any Updates here ? Maybe possibilities now in v17 ?

     

    Thanks!

  • Hi Josef,

    nothing in v17 mr-1.

    Try this rule and see how you go. You could try putting your mail server in the destination network instead of any. I do have logging enabled which doesn't show on my small screen.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian and thanks for your reply !

    I tried that already, but it seems that the Business WAF-Rule hase more priority instead, even when i set this Rule you mentioned at the Top of the List.

    I think that's because the WAF-Rule is monitoring Datastream on Port 443 and ignores the Rule above or underneath.

    The only way i think how this could be done is to implement the "During Scheduled Time" Section inside of Business-Rules.

    I don't know really how to realize that request of my customer atm, because i cannot simply disable the Exchange-Service during the "non-office-times". Only client-connectivity should be limited to work hours.. maybe i take a look at third-party-tools that manage the restriction on the Exchange-Machine itself, but i am not a friend of modifying non-supported Third-Party-Applications on MS Exchange, because of loosing support on Upgrades (for example).

    Hope that Sophos can do here something in the (near) Future ?

    Regards,
    Josef

  • Hi Josef,

    don't give up yet, ask your reseller and submit a ticket to Sophos.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Josef,

    I could be reading mr-2 notes incorrectly, but I think the fix you are looking for has been included.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.