This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

confd-client documentation

We want to migrate some large firewall rules (iptables) to some ASG V9
machines. As this can't be done directly via the Webinterface of the ASGs
I was wondering if it is possible to do the migration by using the 
confd-client. Any information about confd-client command-line options 
for adding/modify firewalls rules would be very helpful for us.

Regards
sakul


This thread was automatically locked due to age.
  • Hi, sakul, and welcome to the User BB!

    A single Firewall rule in V9 can generate dozens of iptables rules. I'm not optimistic about a good answer to your question. How would you get the internal reference names of the Service, Host and Network definitions inserted into your existing rules so they could work with cc? In any case, when you were finished, I doubt that Astaro/Sophos would support the result. Have you asked your reseller or Astaro/Sophos about this approach?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    thank you very much for your quick response.

    What we actualy wanna do is to insert firewalls rules into the ASG. We have a large set of iptable rules and we need to import them into ASG.
    At the moment I don't know how we can get the internal references of rules/services/hosts etc. but I wondering if this could also be done with cc (maybe there exists an option to get these references).

    I will contact Astaro/Sophos about that. Maybe they can provide us some documentation about cc.

    Best regards
    sakul
  • Regarding the question, is there any documentation on this tool at all?

  • Hi Efren,

    I would start with https://community.sophos.com/products/unified-threat-management/f/general-discussion/21326/astaro-useful-shell-commands.  There is a document with all of the available commands, but I'm not sure if it's available to users.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA