Looking for best practices when using more than one Sophos product.
Example, We use Sophso XG firewall, Sophos Wireless Access Points, Sophos Central Endpoint and Servers.
Is it best practice to have the Endpoint or the Firewall scan internet/web related content? Or both, where the scan process is being prerformed twice during the user expereicne?
Is it best practice to have the WAPs Centrallly managed or when a Sophos firewall is present, to have the WAPs manged locally at the firewall? I'm leaning towards locally especially for the multiple mesh network feature.
Is it best practice to filter web content only at the endpoint? Or at the firewall? Or at both, thus scanning the content twice during the user expereince. I have had to allow some websites at the fireewall only and others at the endpoint clients, rarely do i have to enable at both locations, but even then that is double the management and time.
Some best preactice guidance for which service is strongest/best in the layer woudl help me and I'm sure other administrators as well.
Thank you.
John