Greetings,
I am using Sophos XG 230 firewall with SFOS 17.1.4 MR-4 running. I used to have 5 public IP addresses, each IP was configured on a separate port as DMZ zone and port forwarding was done from the firewall policy (Business Application Rule). Now, we are going to have 15 public IP addresses, but in this case I won't be able to use same scenario because of the physical port limitation in count. I was reading a lot about using alias, but truly speaking it was not so clear in my case.
Let's assume the following:
What is the best way to configure those 15 servers with my 15 public IP addresses and keep everything secure?
Regards,
Hi,
Alias are simple "one top" IP Addresses on an Interface.
https://community.sophos.com/kb/en-us/123095
https://community.sophos.com/kb/en-us/126541
There you will find couple of information about this.
__________________________________________________________________________________________________________________
Greetings,
According to the links, I should do the following (For an example):
I will have two servers with the following IP addresses:
I need to create two aliases for the public IP addresses and choose WAN interface for them (10.10.10.14)
Physically, I will be using 1 LAN port and 1 WAN port. But, my question here is the Zone as well. Should I use an extra Ethernet Port for DMZ and assign an IP from my servers network (192.168.1.200 for example), or how to do it?
Regards,
Unless in bridge mode each port needs its own address range, so when you create you DMZ it will have a 192.168.99.1 for example. You would assign the aliases to the external interface (WAN) and use business rules to provide access to the servers regardless of which network they (LAN type) are in.
Ian
XGS118 - v21.5.0
XG115 converted to software licence v21.5.0
If a post solves your question please use the 'Verify Answer' button.