Hello everyone!
I'm brand new to the world of UTMs, and I stumbled upon them (and Sophos) because I'm trying to better secure my network, so I'm planning on buying a mini-box/network PC to install/run Sophos UTM on. I'm trying to perform country/region blocking, but I'd also like better overall security of my network--wifi included--because I have a home file server with various sensitive documents.
I asked a previous question regarding how the UTM was to be positioned on the network, and it appears that for my situation I have two possibilities (I had to do some adjusting to the spacing, so I hope this appears correctly!):
A) Incoming Internet (ISP Modem) ----> WiFi Router ----> Sophos UTM ----> File Server/Wired connections
/ | \
All wireless devices
With this configuration, only the router is open to the net. If it's hacked, then all the attacker gains is free internet access. ;-D However, I can't perform country/region blocking since the router is outside the UTM.
B) Incoming Internet (ISP Modem)----> Sophos UTM ----> WiFi Router
/ \
All wireless devices File Server/Wired connections
With this configuration, I can perform country/region blocking, and the file server is secure from hacks from the internet...but in theory, someone could wirelessly hack the WiFi router--less likely, but I've been told there are still "wardrivers" out there--and if they do, they potentially gain access to the entire network.
So, after thinking a bit, I'm wondering: is the following configuration possible? (and practical?)
C) Incoming Internet (ISP Modem)----> Sophos UTM (MULTI-NIC mini PC)
(eth port 1) (eth port 2)
/ \
Wi-Fi Router File Server
/
All wireless devices
That's the only configuration I see that would allow me to accomplish what I'm trying to do. Failing that, does anyone have any experience with using the Sophos UTM to COMPLETELY REPLACE their wireless router? Some of the mini-PC's I'm considering buying for the UTM come with wireless connectivity built in, but I'm very worried about their broadcast range capacities (I purchased the wifi router I have now to upgrade a previous router that had range/connectivity issues).
I know this is complicated, and I appreciate everyone's time! THANKS!
This thread was automatically locked due to age.