Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Moving from Managed Firewall to Sophos

We currently have a managed firewall with our ISP, along with external IP Address that we use,

We are wanting to save money by bringing this in house, but of course this comes with questions and problems mainly for me....

So i could do with some guidance on how to make sure that I setup the interfaces correctly and that I can get out on the web lol

Currently all traffic go through the UTM Device, Such as Email (inbound and outbound scanning), and HTTP/S (content filtering)

But also we have servers within the internal network that need access to the over internet so I presume I would need some NAT solution for this, but virgin call this a security policy change request, I have copy of the juniper firewall Config but have requested an up to date version of this,

And of course still reaming full protected

Thanks



This thread was automatically locked due to age.
Parents
  • You might not be looking for this answer, but in your managed firewall you currently have, you (most likely) also pay for knowledge (both in managing the firewall as in best practices for preventing trouble).

    The questions you ask give me a feeling that at this moment there's not a lot of knowledge inside your organisation about managing and maintaining firewalls in general. First question you need to answer for yourself is whether or not you trust the current level of knowledge in your organisation enough to setup such a crucial piece of equipment as a (next-gen) firewall.

    I think your best bet might be to get a consultant involved in setting everything up and select them to not only set everything up, but to educate you in the process and have them explain why things are setup the way they are. That might be the best way to get a jump-start into managing your own Sophos environment. At the same time you can start reading in this Sophos community like Douglas suggested.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply
  • You might not be looking for this answer, but in your managed firewall you currently have, you (most likely) also pay for knowledge (both in managing the firewall as in best practices for preventing trouble).

    The questions you ask give me a feeling that at this moment there's not a lot of knowledge inside your organisation about managing and maintaining firewalls in general. First question you need to answer for yourself is whether or not you trust the current level of knowledge in your organisation enough to setup such a crucial piece of equipment as a (next-gen) firewall.

    I think your best bet might be to get a consultant involved in setting everything up and select them to not only set everything up, but to educate you in the process and have them explain why things are setup the way they are. That might be the best way to get a jump-start into managing your own Sophos environment. At the same time you can start reading in this Sophos community like Douglas suggested.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Children
  • it is a shame i cant do a reply to all, i do appreciate all of the comments and suggestions, just to give a bit more back ground, I've been using the UTM device in question for sometime and i do feel comfortable in doing certain things,  that being said i do know i have the support of Sophos at hand should i need it, and i have used it for 1 or 2 things,

     

    i understand that a consultant might be a good option and in some cases you could be correct however, when the change over happens i will have a period of flexi time to get myself up to speed and should i need it i will contact Sophos, maybe i'm over thinking things considering the ownership will be down to myself but i think i should be OK.

     

    i will add a visio  diagram and give you what i think should be correct, and if there needs to be any changes then i will update them.