Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Automatic firewall rules Vs Manual firewall rules

Hi All

I am trying to get a better understanding of the differences between the 2.  I am using UTM 9 on SG125

I have multiple IPSEC sites (Grouped as VPN-0-All Branches) all connecting to Head Office (VPN-Z-LAN).

So I do not enable automatic firewall rules but set to manual rules as follows Key being 1&2 (Allow between Branch & HO Any + HO & Branch Any)

My application (using single port for connection) connects fine under above but I cannot access anything else such as web access to remote router or remote desktop via IP address

If I enable rule 4 (Web Surfing) I can access remote router but still cannot remote desktop to a machine at branch using IP address i.e.

 

However if I let UTM create an auto rule all works fine (even if I have all others disabled) e.g.  In this example have allowed creation of auto firewall rule between Branch B and Z Any

In this case all works fine. So what's the difference? [:^)]

Is it the case the in manually created rule "Any" is not the same thing as "Any" on the auto created rule or something else?

 

Any insight would be appreciated



This thread was automatically locked due to age.
  • I can only assume auto fw rules ignore the interface bindings - From my tests this seems to be the case.

    I simply did not understand the implications of binding to an interface - Not sure why but it just seemed like common sense to me!

    I had always used auto fw rules but as as my traffic is all site to site vpn with very limited services required - it would make sense to move to manual rules and restrict to only those service.

    However I will keep you comment in mind regarding auto rules for non site to site vpn should I require them.

    Thank you for your help. Life makes sense again!

  • I have done some initial reading and now understand the implications if Input/Output vs Forward a lot better.

    From what I can see there is certainly a difference with automatic rules and they ignore interface bindings to create proper forward rules.

    I take your point on #3 (although I suspect it will be a hard habit to break!) -  I will look at the Rulz guide in more detail.

    Thank you as always for your guidance, much appreciated.