Guest User!

You are not Sophos Staff.

The Web Protection – Per-connection authentication Feature??

The Web Protection – Per-connection authentication for multiple users on the same source IP address, enforcement of tenant restrictions for O365, and X-Forwarded-For Header support for up-stream load balancers and proxies Feature??  

Noticed its only available on the old Web Proxy, so was wondering why this addition wasn't added for the DPI engine, Is there any specific reason for this??  

Thanks

JK



Add nane
[edited by: john_kenny at 1:17 PM (GMT -8) on 8 Dec 2021]
Parents Reply Children
  • Surely the web protection - Enforce Tenant Restrictions for O365 would also be beneficial on non-Legacy Web protection filters, especially seeing how Microsoft 365 / Azure traffic benefit's going through the DPI engine now??  I do not have enough knowledge of the packet flow through Sophos Firewall OS to have any say on this subject but surely at some point in time in the future the Legacy Web Proxy will be EOL right??  So, my point being will these Web Protection changes be applied to the DPI engine Web Protection at any time soon I.E. is this on the roadmap??

    Going to try these Enforce Tenant Restrictions for O365 changes soon anyway it's just a pain having to create or modify Firewall rules to run with the Legacy Web proxy too??

    But many thanks for your reply, its much appreciated as always!!!

    Thanks

    JK

    JK

  • There is no plan to EOL the web proxy.  v19 includes development of new features only available in the web proxy.


    The DPI mode is "deep packet inspection" - it has the ability to watch traffic but if there is any attempt to modify traffic then then client/server detects it and complains.  DPI mode cannot add headers because that would change the size of the tcp/ip packet.

    The traditional web proxy, on he other hand, has full ability to modify the traffic in flight, including changing headers.

    The Tenant Restrictions for O365 is a feature provided by Microsoft that requires the XG to add a header to all requests.  Therefore it can only be done by the web proxy.


    All web features within the XG that are available only by the web proxy are marked as such.  Those features cannot be supported in DPI due to technical limitations, not because we have not bothered to.