This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN - Block-Outside-DNS?

Hi all,

 

I just have a quick question regarding the Sophos SSL VPN within UTM 9 - does it automatically block outside DNS from being used? 

The reason I ask is because I'm setting up our Sophos VPN so we can retire our IPCop server, and on that we had to configure it to push the block-outside-dns setting, so it would then automatically obtain the DNS addresses from the VPN connection, rather than the local router. Is this something I would also need to configure with the Sophos UTM? 

 

Regards,

 

Rob



This thread was automatically locked due to age.
  • Thanks for putting that all together in one spot, Rob.

    1. In your SSL VPN Profile, put your LAN(s) and the "Internet" object in 'Local Networks'
    2. On 'Remote Access >> Advanced', list the internal IP of your local DNS server, followed by the IP of "Internal (Address)"
    3. In 'Network Services >> DNS', add "VPN Pool (SSL)" to 'Allowed Networks'
    4. In 'Network Protection >> Firewall', confirm that you don't have a rule that would allow VPN users to do DNS requests directly to the Internet.

    You also might want to take a look at DNS Best Practice.

    Cheers - Bob

  • Many thanks for this, Bob. Very helpful!