Hello We use a UTM 9 firewall (firmware 9.006-5). I want to use EP AV and we testing now to remove Mcafee and install Sophos EP
We use a proxy in standard mode. I made a firewall rule:
Groups ("DNS Groups", because the DNS names contains multiple IP adresses)
Broker Service
Allow http and https traffic to
all.broker.sophos.com
Update Servers
Allow http and https traffic to
dci.sophosupd.com
d1.sophosupd.com
d2.sophosupd.com
d3.sophosupd.com
dci.sophosupd.net
d1.sophosupd.net
d2.sophosupd.net
d3.sophosupd.net
Still this is not working, my firewall keeps blocking addresses:
12:20:25 Default DROP TCP
156.5.5.130 : 4932
→
23.62.99.57 : 80
[SYN] len=48 ttl=126 tos=0x00 srcmac=88:e0:f3:6a:64:0 dstmac=0:1a:8c:f0:35:a0
When I make a rule with network 23.62.99.0 /24 to allow 80/443 it works, but there is a chance the address is in a other network next time I update the Sophos EP client.
Mcafee uses EPO, my experience is that this works better, cliets get there update from the EPO server, maybe UTM 9 can work this way?
This thread was automatically locked due to age.