Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Guest network access. Packetfilter does not block as expected

Hello everyone,

I recently discovered a problem with my Guest-WAN configuration
I have to separate guest interfaces (VLANs on a separate phy. NIC of the UTM). IPs are separate from corp. network

I used 's guide for configuring the rest of the system to ensure separation

The problem I discovered is the following:

From the guest network I can access ALL internal websites

Other services are not possible

Our HTTP proxy runs in transparent mode. Guest network is set to skip source mode. Allow HTTP/S for skipped networks is enabled! (Due to requirements for some internal networks)

Packet filter rules are as follows:

 

The reachable internal websites IPs are included in the obfuscated green network group of rule #1

Any ideas why this happens?

Again clean separation of guest from anything else proves to be more complex than expected :(

 

Best regards for your help



This thread was automatically locked due to age.
Parents
  • i think you describe your problem:

    "Our HTTP proxy runs in transparent mode. Guest network is set to skip source mode. Allow HTTP/S for skipped networks is enabled! (Due to requirements for some internal networks)"

    just for testing disallow http/s traffic for skipped networks in the http proxy.

    can guest network now still reach internal websites?

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Hello

    sorry for the late reply.

    I tested disabling HTTP/S access for skipped host/nets

     

    Same issue. Access to the internal sites is still possible

    Best regards

  • please test following:

    split your first firewall rule in 3 single rules.. one rule for one network.

    put the guest to internal drop first and select log traffic in this rule.

    open paket filter log and test again.. what do you see?

    EDIT:

    please also check if you have more than one webfilter profile which maybe matches your guestnetwork...

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

Reply
  • please test following:

    split your first firewall rule in 3 single rules.. one rule for one network.

    put the guest to internal drop first and select log traffic in this rule.

    open paket filter log and test again.. what do you see?

    EDIT:

    please also check if you have more than one webfilter profile which maybe matches your guestnetwork...

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?