This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Questions about Security Heartbeat

I have a few questions about Heartbeat. I'm wanting to turn it on. I'm licensed, I just need to apply a setting onto a firewall rule now at this point.

 

1) Sorry if it's a dumb question, it just seems like many devices do not qualify to be sending a "heartbeat" to the XG, so what's keeping the XG from blocking those devices? Such as mobile phones, NAS, etc. Is it just that the XG only considers a device to require a heartbeat IF it has Central Endpoint installed at some point in history? All other devices pass Okay?

2) Given that many infections now spread from computer to computer such as Ransomware, wouldn't it be more effective to apply a HB requirement on a LAN-LAN rule or similar? This would at least help to prevent virus's from spreading in the network right? Everything I've seen so far, people apply HB requirement to the LAN-WAN rule so it was confusing. I get that their method would prevent BOTNET type traffic from calling home though, so that's good.

3) Another reason I could see to not apply the HB requirment onto the LAN-WAN rule is; what if you need to troubleshoot the device remotely, or if you just need to clean up a PUA and want to do it from the Central portal. Wouldn't that command to Clean never reach the infected device with the PUA since the XG would be blocking it?

- I thought perhaps a workaround might be to make an additional LAN-WAN FW rule above the main LAN-WAN rule which would allow traffic only to Teamviewer, Splashtop servers, and Sophos Central servers etc. Leaving all HB settings off on that rule, but turning them on for the main rule below. That way I could still troubleshoot remotely, log in remotely, and issue commands to clean PUA's remotely too. Does this sound accurate?



This thread was automatically locked due to age.
Parents
  • I will try to help ...

    for each rule (within Firewall) there is a requirement to set source & detination HB permitted

    rules must be properly order if you have devices that do not provide a heart beat.

    LAN-LAN HB can be configured if LANs are on different interfaces/VLANs.

    LAN-WAN rules usually applied only for Client HB

    If you have servers in a DMZ, then HB for Client and Destination can be applied.

    the HB would be come degraded if the system has changed that opposes the policy (set within Sophos Central), or that the application is not on the approved list. depends on how strict you want to be.

    The FW does not control access to the clients (with HB) except if you block HTTPS entirely (which is pointless as the client would never get updates). The command to "Clean" that is sent from Sophos Central would work, as the FW would only check whether the HB is degraded and doesn't stop Sophos Central from sending commands to the client (to update or clean).

    the rules decide how the access is granted.

     

    hope this helps

Reply
  • I will try to help ...

    for each rule (within Firewall) there is a requirement to set source & detination HB permitted

    rules must be properly order if you have devices that do not provide a heart beat.

    LAN-LAN HB can be configured if LANs are on different interfaces/VLANs.

    LAN-WAN rules usually applied only for Client HB

    If you have servers in a DMZ, then HB for Client and Destination can be applied.

    the HB would be come degraded if the system has changed that opposes the policy (set within Sophos Central), or that the application is not on the approved list. depends on how strict you want to be.

    The FW does not control access to the clients (with HB) except if you block HTTPS entirely (which is pointless as the client would never get updates). The command to "Clean" that is sent from Sophos Central would work, as the FW would only check whether the HB is degraded and doesn't stop Sophos Central from sending commands to the client (to update or clean).

    the rules decide how the access is granted.

     

    hope this helps

Children
No Data