Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Filtering

I installed Sophos UTM OS today for the first time. I'm new to networking etc so I'm not sure how all this stuff works. I blocked a few sites but they are not being blocked. Is there some client config I need? I think I skipped a few network settings during first time setup. Please help
Thanks
Nicholas
@NicholasHayman


This thread was automatically locked due to age.
Parents Reply
  • The UTM is a specialized firewall that really needs at least 2 network cards. The wifi in most hardware setups is not supported at all in Sophos UTM. A very few of them could be supported as an access point, but still not as a connection to another wifi network, it's not functioning as a normal wifi card in your everyday computer.

Children
  • No, in a VM you can create the UTM but then you can also create 2 NIC's using the virtualization software. You can then see both NIC's during setup and setup 1 as internal interface and the other as your external interface.

  • So in that case I do have 2 NICs? I did see them both during setup but I left the external WAN interface because I didn't know how to configure it.

  • I think in the interfaces screen that you showed us, you can in that case add another interface. Call it External (or WAN or whatever) and select the remaining NIC as the underlying hardware.

    In the VM-host you need to connect this virtual NIC to your internet connection and you can configure it in the UTM just as you would with a normal router (or PC), I don't know your provider, so I don't know how to set that up exactly.

  • Can I set the UTM to automatically get the WAN settings from my Router. I use my ISP provided modem/router unit.

  • That depends on how your ISP modem/router is setup. But usually if it's also a router (where you could also connect a computer that then automatically works), you can indeed automatically have the interface setup by configuring it as a DHCP interface

    By selecting "Dynamic IP" the interface will request an IP-address from your modem. Also make sure IPv4 Default GW is selected so your UTM knows where to send internet requests.

  • Hi,

     

    Thanks for the guide although it doesn't seem to pick up an IP address from my router which is weird because apart from that DHCP on my network works fine. On my UTM IPv6 Default GW isn't an option but does that matter as IPv6 is not used much at the moment? Is there anyone here in the forums who uses Sophos UTM Home with a BT Infinity internet connection?

     

    Also just checking clients that should have content controlled by the UTM don't have to be plugged in through the UTM do they? As long as the clients are connected with the same LAN with the same subnet etc it should be fine? As I say this is the first time ever that I've tried to implement an advanced network security system.

     

    Nicholas

     

  • Clients don't have to be physically connected to the UTM. Being in the same subnet will suffice. They do however need the UTM as their default gateway so traffic to the internet travels through the UTM.

    I'm afraid I cannot help you further with your Infinity connection. IPv6 doesn't have to be turned on if not used.

  • Guys, I've read through this and I think, Nicholas, you might want to do a factory reset of your UTM VM and start over, but it's really not clear what you're working with...

    1. What hardware are you using to run the virtualization - a laptop?  What CPU?  How much RAM does it have.  Which virtualization?
    2. How much RAM and how many Processors have you allocated to the UTM VM?
    3. How many users will be on simultaneously?  What and whom do you want to control/protect?  Are you only interested in anti-virus for web surfing and filtering your kids' web accesses?
    4. What connection speed do you get from BT?
    5. Can the BT modem be put in bridge mode so that the UTM can have a public IP instead of something in 192.168.x.y?
    6. Is the BT modem also a wireless router, or just a router and you have a separate wireless access point?

    Cheers - Bob

  • Hi Bob,

     

    1. Yes, a laptop. Intel Core i5-5250U CPU, 4GB RAM, VMWare.

     

    2. 2GB ram and 1 processor

     

    3. Probably 5 at the most at any one time. I don't want to use the really advanced features but things like anti virus, web filtering and basic firewall I would like to use.

     

    4. I get 30mbps down and 6mbps up.

     

    5. To be honest I'm not sure.

     

    6. Yes, it is a modem and wireless router in one although I have a separate Ubiquiti UniFi wireless access point too, to extend the coverage.

     

    Thanks

     

    Nicholas