This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Question about Heartbeat via MPLS

Hi Guys,

I had a question about Sophos Heartbeat issue. I am attaching the network diagram. In short, there is a central firewall (XG) and all the branch firewalls (XG) are connected via MPLS as a WAN ( they get their internet from the central firewall ) . All branches and the central firewall all have endpoints which are installed with the CIXA ( only one central account for all the firewalls and branches ). We have synchronized each of the branch firewalls with the single central account. My question is, is it possible to see ALL the branch endpoints to send their heartbeat status to the central firewall ONLY. We dont mind de-registering the branch office firewalls for synchronized security. Is this possible ?



This thread was automatically locked due to age.
Parents
  • Having run a setup similar to this i can say yes it does work, be aware you will need to turn off the heartbeat on the branch XG's so it gets passed through, this IMHO defeats the point of the heartbeat and so a revised setup with the heartbeat going to the branch XG's and then having a VLAN for WAN traffic and VLAN for site to site routed traffic between the XG's . This allows for the branch sites to be able to keep heartbeat and also allow for local isolation using the heartbeat, allows for isolation on the any machines on the actual site. bit more config to do but it works and spreads the load for Heartbeat, authentication, web proxy etc

    Sophos XG Engineer

    Sophos Silver Partner

  • Heartbeat will be establish between the Client and the first XG, which answers the HB IP. 

    Endpoints and XG Firewall communicate through an encrypted TLS connection over the IP address 52.5.76.173 on port 8347.

     

    So if you route this traffic properly, the correct XG will answer. 

    XG will intercept this traffic. 

    Same for VPN Technologies like SSLVPN/ IPsec. 

     

    There are couple of feature request to have multiple XGs connected to one Endpoint at the same time, but it is not easy to implement. 

     

    __________________________________________________________________________________________________________________

  • Couldnt get this info out of support when we first tried using the heartbeat so had to switch it off on the branch XG's initially, but if you passing through the heartbeat to another XG it kind of defeats the point of it IMHO as you want to stop the traffic at the earliest point which would be the branch XG's

    Sophos XG Engineer

    Sophos Silver Partner

Reply
  • Couldnt get this info out of support when we first tried using the heartbeat so had to switch it off on the branch XG's initially, but if you passing through the heartbeat to another XG it kind of defeats the point of it IMHO as you want to stop the traffic at the earliest point which would be the branch XG's

    Sophos XG Engineer

    Sophos Silver Partner

Children