Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DMZ, help needed for UTM 9.4 (software) configuration.

Hi,
Need help with setting up a DMZ network on my UTM 9.4 firewall computer.
I have tried to set this up for a long time but with no luck.
And I have also tried a lot of different settings (from forum and Internet) for my DMZ but it never works.

I have 3 NIC:s with following configuration:
eth0 = Internal with 172.21.21.10/16
eth1 = External with a static IP address xxx.xxx.xxx.xxx/27
eth2 = DMZ with 10.0.0.1/28

DNS Allowed network =
Internal (Network)
DMZ (network)

NAT Masquerading rule =
Internal (Network) - External (WAN)
DMZ (Network) - External (WAN)

Firewall rules =
DMZ (Network) - reject - Internal (Network)
DMZ (Network) - allow - External (WAN) (Network)
DMZ (Network) - allow - DMZ (Network)

What's wrong? More NAT rules? More Firewall rules? More what???

Please give me some hints how to config my UTM.

rgds Roland



This thread was automatically locked due to age.
  • Hi, Roland, and welcome to the UTM Community!

    It's your firewall rules.  First, everything that isn't explicitly allowed is blocked.  Things like VPNs and Proxies create hidden firewall Allow rules.  It appears that you already have understood that the UTM is a stateful firewall, so it automatically allows inbound responses to requests that were allowed out.

    Instead of rejecting traffic DMZ -> Internal:

    • Internal (Network) -> {services} -> Any : Allow
    • DMZ (Network) -> (Services} -> Internet : Allow

     You don't need to allow traffic between devices in the DMZ as all traffic between devices with the same subnet on the same Ethernet segment goes directly between the devices and does not transit the UTM.

    All good now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?