What are the domains or FQDNs to allow for access to Live Discover?
The goal is to allow the Sophos MDR team to access an endpoint that is in red status and getting blocked by the firewall.
When a device behind the Sophos firewall goes into a red heartbeat status we have a rule that blocks outbound traffic from the possibly infected host. The problem is that the MDR team cannot access the host. Even when we put a firewall rule above to allow all the domains (FQDN) per Sophos' article, the device is still offline in Live Discover. I've opened ticket 06978860 with support and been back and forth for weeks with no progress as they can't tell me the correct domain or FQDN for Live Discover.
I tested this on my laptop. I have a rule to allow all the domains per the article (https://doc.sophos.com/central/customer/help/en-us/PeopleAndDevices/ProtectDevices/DomainsPorts/index.html#domains), followed by a rule to drop internet traffic. My laptop goes offline in Live Discover when I do this. Yet I’m able to browse to sophos.com web site and get Sophos Endpoint updates. I don’t think the list of domains in the article includes the domains required for Live Discover. Have you done this same test on your end to verify? Please test it out and let me know what you find and if you can identify the domain responsible for Live Discover so we can get this resolved.