Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Location of UTM / XG and Gateway or Bridge

Hi,

I need help with my basic network topology, where to put my Sophos device at home. I currently have a Unifi system, hoping to sell that to get a Sophos AP  to make it one package

but that is not going to happen for awhile and it is the WiFi I have to use.

Can I setup the UTM or XG outside of the current setup? Most descriptions have the Sophos device  between a router and switch. I played around with it like this:

Cable Modem---Unifi USG (Gateway)---XG Firewall or UTM---Switch---LAN/WiFi AP

Also thinking maybe this is better:

Cable Modem---XG Firewall  or UTM---Unifi USG Gateway---Switch----LAN/WiFi AP

The USG "Unifi Security Gateway" is supposed to be a security appliance, it acts like a brain connected to the switch but it is pretty dumb actually, it doesn't do anything security wise besides a stateful firewall unless programmed with command line/IP tables. Wanted a UTM really but they were pretty deceptive w their advertising. The gateway and switch should just be together as one router. I have every device isolated on the network pretty much and I think even if I didn't all internal traffic involves the USG, not just the switch.

My thinking is maybe everything is more secure without the gateway being directly exposed to the WAN. If it was compromised it might give a base to attack from which is more difficult to detect as it'd be from that IP.

I am not sure if I would be better off running the XG or UTM as a gateway on the outside there w/ the LAN and WiFi switched by the current setup in bridge mode or run the UTM or XG as a bridge.

Thanks for your help!



This thread was automatically locked due to age.
Parents
  • Hi and welcome,

    home user limitations,

    UTM - maximum of 50 IP addresses regardless of hardware.

    XG - unlimited IP addresses up to your hardware limits, memory being the main one should be 6gb, currently issues raging in the XG forum on this subject. 4 cores of CPU, where this comes into limitation is if you have high speed connections >100mb/s.

    Put your modem in bridge mode then choose your device. Home use XG isn't too bad, depending on your level of paranoia?

    UTM is good for small users at home, has lots of features, not all are available to a home user.

    Me, currently I have just put my XG back into service with aim of bringing my home security to UTM level.

    I have Sophos APs on both machines, for home use you are better off getting a good netgear or similar device. Not managable by either UTM or XG, but have better throughput.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Do you or anyone know if there is a way to run them on the very outside of a network? I do not want the Unifi equipment exposed to the internet and it would reduce the reports I can get on what is going on if that firewall is  on the outside.

Reply
  • Do you or anyone know if there is a way to run them on the very outside of a network? I do not want the Unifi equipment exposed to the internet and it would reduce the reports I can get on what is going on if that firewall is  on the outside.

Children
No Data