This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Rules for internal LANS

We have recently purchased a Sophos UTM and I'm in the process of setting it up to replace our existing Juniper firewall. I'm new to Sophos and hopefully this is a simple question.

We have 5 different sites in our company's network. Each building has its own subnet. Our internet provider links our sites together through an MPLS solution. All internet traffic is routed through 1 site. We're replacing the Juniper at that main site with a Sophos UTM. All of our internal traffic from 5 subnets routes through a single interface on the firewall. I've labeled the internal port "LAN" and the external "Internet". We currently have manual routing rules in place to route traffic to all of the internal subnets through the LAN port and I will be setting those up on the UTM, as well.

Juniper uses the "zone" concept to make it very easy to set up firewall rules based on interfaces. ie All traffic from this interface to that interface-allow. If I want to allow traffic for a certain service from all internal subnets to the Internet, what's the best way to do that?



This thread was automatically locked due to age.
Parents
  • I'm not sure if I've understood your infrastructure: you have 5 sites/subnets which are all routet to one site/subnet. And there is the Juniper/Sophos device with ONE LAN interface, which routet all the traffic between the 5 sites/subnet and the internet?

    So you have to create different VLAN interfaces for each subnet on the LAN interface, which you can also use in the firewall ruleset. After creating the VLAN interfaces you should have also the network definition for that VLAN available in the firewall. Therefore you can create which services are allowed to/from the different subnet and the internet.
Reply
  • I'm not sure if I've understood your infrastructure: you have 5 sites/subnets which are all routet to one site/subnet. And there is the Juniper/Sophos device with ONE LAN interface, which routet all the traffic between the 5 sites/subnet and the internet?

    So you have to create different VLAN interfaces for each subnet on the LAN interface, which you can also use in the firewall ruleset. After creating the VLAN interfaces you should have also the network definition for that VLAN available in the firewall. Therefore you can create which services are allowed to/from the different subnet and the internet.
Children
No Data