Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Real Time FW Rule Checking? Need Suggestions on Debugging FW Policies

Hey Folks,

I have brought up Sophos UTM in my lab (@ Home), and trying to get familiar with the system.  I have implemented Fortinet and PaloAlto in the past, and having a bit of trouble with Sophos.  I am still trying to get the hang of the user interface and "sophos" way of doing things.  

I have various L4 rules written, but having a heck of a time trying to debug traffic, and which rules is being tripped.  I can open up the Log files, but that is just a pain.  There must be a better way in Sophos.  

In Palo Alto for example, I can go to either Web Filter or FW and type in the Source or Dest IP.  That will quickly show me which rule allowed the traffic in,and which rule blocked it.

This makes for very easy debugging.  Does Sophos UTM Home have this feature?  How are you guys debugging policies?

- Ton


This thread was automatically locked due to age.
  • Check out #1 in Rulz.  There's no combined log file.  Allowed packets aren't logged unless you explicitly select logging in the rule.  Have you tried the 'Search Log Files' tab?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?