So, it's 'Internet[ASG]LANs' and the DMZ LAN contains the WAF? So the traffic from the internet is DNATted to the WAF, and it sends the web requests to a server in the DMZ?
If that's right, then I guess it might work, but nothng is getting to the WAF that triggers IPS. Can you create an HTTP flood to the WAF from the internet? What happens if the HTTP server isn't listed on the 'Advanced' tab of IPS?
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005
So, it's 'Internet[ASG]LANs' and the DMZ LAN contains the WAF? So the traffic from the internet is DNATted to the WAF, and it sends the web requests to a server in the DMZ?
If that's right, then I guess it might work, but nothng is getting to the WAF that triggers IPS. Can you create an HTTP flood to the WAF from the internet? What happens if the HTTP server isn't listed on the 'Advanced' tab of IPS?
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005