Hi,
I read Rulz, but I am still having difficulty understanding what's going on. I am trying to enable VPN services such as WiTopia and VPN unlimited, (which use IPsec and OpenVPN respectively, as far as I know).
I created a firewall rule for the entire internal network to allow VPN protocols out. VPN services still do not function, however, and I can see the attempted connections getting dropped. It does not APPEAR to be intrusion prevention, but that remains to be seen.
The firewall rule I created is:
- Sources: Internal (Network)
- Services: VPN Protocols
- Destinations: Any
- Action: Allow
- Time Period: Always
- Log Traffic: checked
- Source Mac Addresses: none
And the rule is enabled.
In order on Intrusion Protection page:
- Global - IPS status enabled, Local networks = Internal (Network) only, policy/restart policy = drop silently/drop all packets
- Attack Patterns - everything checked, everything dropped
- Anti-DOS/Flooding - no options checked
- Anti-portscan - Enabled, Log event only, limit logging
- Exceptions: none
- Advanced: nothing added here (everything is blank)
I am not really sure where to look next. It's highly possible I am misunderstanding how attack patterns work, but there is nothing obvious to me as to why the VPN connections are being dropped.
Also, I AM blocking most of the world via countries, however the connections in question are going to US-based VPN sites. The US is not blocked at all.
Thanks in advance for any insight, it is much appreciated. I am new to Sophos UTM (home edition) but I am eager to learn.
This thread was automatically locked due to age.