This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Transparent mode before or after router for traffic inspection?

I'm planning on installing the home use version of XG in order to see if I can get better information on what's going on on my network. I currently have an EdgeRouter outputting snmp to Observium and sflow to SFlow Trend, but SFlow Trend is not very good (looses connection) and doesn't keep logs, so I thought that I would give this a try. If Sophos can't do that please let me know, but from what I've read it seems to fit my requirements.

My question is, can Sophos know what is going on at the individual PC level if I put it before the router or would it have to go between the router and the switch?

A) Modem --> Firewall --> Router --> Switch --> AP

B) Modem --> Router --> Firewall --> Switch --> AP

 

I know I can probably decommission the EdgeRouter and have Sophos do routing, but at this point I'm just going to test it out and see if the hardware I purchased (quad core Celeron mini PC) is good enough at handling this.



This thread was automatically locked due to age.
Parents
  • Hi  

     

    Option B will be the best option. You will be able to control and log traffic separate for each client.

     

    If you place firewall between Modem and your router all traffic will be NATed with your Router IP and you won't be able to different traffic between multiple clients.

     

    Good Luck!!!

     

    Regards, Ronak.

Reply
  • Hi  

     

    Option B will be the best option. You will be able to control and log traffic separate for each client.

     

    If you place firewall between Modem and your router all traffic will be NATed with your Router IP and you won't be able to different traffic between multiple clients.

     

    Good Luck!!!

     

    Regards, Ronak.

Children