Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAF with single NIC?

Hi, can the WAF (in 9.006) be used in a system with a single NIC?

If so, how many IPs are needed on that NIC? Can a single IP work?

Thanks,
Barry


This thread was automatically locked due to age.
  • Hi Bruce,

    That's what I figured, but I wonder if that could be 'fixed' by Sophos; it would be nice to be able to have the IPS work on single-NIC proxy installs.

    Thanks,
    Barry
  • Once I saw Bruce's comment, Barry, it seemed obvious - how else would the packets even transit the UTM?

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,
    I'm only interested in applying the IPS to HTTP traffic, which is already entering and exiting the UTM as I am using the WAF.

    From my understanding of how the IPS works, I see no reason it couldn't be applied to the WAF traffic as well, even with a single NIC.
    However, it would apparently require Sophos to change something, as it isn't working presently.

    I realize that putting in a second NIC could 'fix' this, but I'm not sure that would be a good fit with our network layout.

    Thanks,
    Barry
  • What about Bruce's suggestion of two VLANs?

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I don't think that'll make things any easier in our environment.

    Thanks,
    Barry
  • You know, I think there are problems with bridging and WAF in V9, so I wouldn't recommend that anyway. 

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • The license count seems rather strange in the single-NIC config... instead of counting the servers protected by the WAF, random DMZ IPs are being counted.

    These IPs are not communicating through the proxy.

    This is troubling as it means that a 10-IP license may not be enough, even though we're only protecting a few IPs.

    The UTM proxy's interfaces are on .20 and .29, /24.

    The protected servers are in a different subnet, via the ASA.

    > count_active_ip.plx --showcount
     count_active_ip: checking active IP addresses
    Active IP addresses:
    10.0.6.21
    10.0.6.241
    10.0.6.15
    10.0.6.19
    Totals: IPv4: 4 IPv6: 0


    Barry
  • Hey Barry, I've sent you an email; I'd like to look at your configuration.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?