This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WebControl / Entrprise Console

Hi,

We use an UTM and all clients use Sophos Endpoint Security. Clients are configured using the enterprise console.

I want to achieve the following:

  1. A group of computers gets blocked for a specific set of websites (filter action on the UTM). The block should always apply. Also outside our network.
  2. All other computers should not be restricted.

Can someone explain what I need to configure to achieve the goals stated above?

Thanks
Robert



This thread was automatically locked due to age.
Parents
  • Hey, Robert. 

    You'll need to create a "Full Web Control" policy on SEC and deploy it to the computers that should have internet access controlled even outside the network. On that Full Web Control policy you would need to provide "hostname" and "shared key" information obtained from your UTM. More information on how to enable the feature and obtain that information here.

    I haven't used this is a while, and to be honest the last time I tried to activate it there were issues with SEC and Sophos LiveConnect preventing it from working. That being said, I also remember a limitation that only the default web policy from the UTM (not web filter profiles) used to be passed over to SEC endpoints. I don't know it this have changed after the latest updates or not so, if this does not work right off the bat with your current config, try changing your default web policy so the users of the computers you want to control have a matching filter action on the default web policy of the UTM. 

    You can check if a computer managed by SEC is receiving a Full Web Control policy by checking "C:\ProgramData\Sophos\Web Control\Policy". If there are files in this directory, the endpoint is receiving a policy from Sophos LiveConnect and as long as the logged in user has a matching filter action it should prevent access to blocked websites.

    Regards,

    Giovani

  • Thanks a lot for the explanation. I wish there was a good documentation on how these two products work togehter.

Reply Children
No Data