Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multiple SNATs with Web Filtering

We have need of splitting our outbound traffic into multiple outbound IPs, while using web filtering. Sophos support is telling me that it's not possible.

Scenario: we have different buildings with vastly different security requirements. Some buildings do SOCII compliant work, other buildings make beer cartons. (literally). Customers in the high-security realm are watching our network through online security firms and they are seeing low security traffic mixed with the high security stuff. We need to segregate off the high security people using a different IP, so we can show that all traffic on that network is secure. There's a big dollar contract hanging in the balance.

We also need web filtering for obvious reasons (including requirements by the same customers). Sophos says it isn't possible.

Does anyone have an alternate way of getting where we need to be?

Steve

 

 

 



This thread was automatically locked due to age.
Parents
  • You can activate a feature that allows you to select the source interface for outgoing web filter traffic.

    As this is done by CLI, you have to ask sophos support before.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Yeah we found that one, but that just routes all of our web-filtered output out a different IP.

    We need to route traffic from CSR Group 1 out one IP and CSR Group 2 out a different IP. All of it needs to be web-filtered.

     

  • you have to create 2 webfilter-profiles with 2 different output-interfaces.

    So you can split groups by IP-range.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • you have to create 2 webfilter-profiles with 2 different output-interfaces.

    So you can split groups by IP-range.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data