Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New XG Country blocking & licensing question(s)

Hi all,
I just found out the new Sophos XG. I installed it on a VM and used the Home User License.
I have some questions:
1) I have 1 physical firewall box and 2 VM's for testing. Is it possible to use 1 license for the 3 XG's (Home)?
2) I have serveral licenses for the UTM 9. I "earned" them for beta testing, can I convert them for the XG's?
3) In UTM 9 there's an option to block from/to/both/none countries (Firewall section).
   I can't find it in Sophos XG. I only want traffic from europe and going to the rest of the world.
   How do I accomplish this? I'm using Web Server Protection<Business Application> (formely WAF)

Going further playing with Sophos XG :)
Cheers,
Pablo



This thread was automatically locked due to age.
Parents
  • Thanks for the reply.
    I made a group of several countries to block but don't now how to make a proper policy.

    I now have the following policy:
    Source:
    Zone: WAN
    Networks: Blocked countries (holding the blocked countries)
    Services: ANY

    Destination:
    Zone: WAN
    Networks: #portB (this is my internet facing NIC (interface)

    Action: Drop


    The rules below I have 2 policies for "Business Application Rules".
    When I apply the (block) policy I'm still able to access the Business Application even when the
    block policy is applied.


    Second question: is it not possible to allow certain countries and make a second policy afterwards to block ANY?

Reply
  • Thanks for the reply.
    I made a group of several countries to block but don't now how to make a proper policy.

    I now have the following policy:
    Source:
    Zone: WAN
    Networks: Blocked countries (holding the blocked countries)
    Services: ANY

    Destination:
    Zone: WAN
    Networks: #portB (this is my internet facing NIC (interface)

    Action: Drop


    The rules below I have 2 policies for "Business Application Rules".
    When I apply the (block) policy I'm still able to access the Business Application even when the
    block policy is applied.


    Second question: is it not possible to allow certain countries and make a second policy afterwards to block ANY?

Children
No Data