Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Usecase of existing FQDN hosts

Hey everyone!

I've been working with the XG Firewall for about a week now and am still excited about all the nice features and just how it looks like.

I want to know if it's okay to delete the predefined FQDN hosts, because the long list of suggestions is more annoying than helpful when creating new policies. Via System > Hosts and Services > FQDN hosts I'd be allowed to delete them, but would this possibly interfere with an important component and restrict my XG in its functionality? Why is there a so large list of predefined hosts?

Thanks for your help in advance!

Best regards,
Leon



This thread was automatically locked due to age.
Parents
  • FormerMember
    +1 FormerMember

    Hi intrusus,

    It is not advisable to delete predefined FQDN hosts, deleting them might cause some issues. If going through the long list is the issue, you might want to use search feature to sort required FQDN host. 

    This details is in help section of the FQDN page: 

    The FQDN host page displays the list of all the available FQDN host.

    FQDN (fully qualified domain name) hosts allow entities to be defined once and be re-used in multiple referential instances throughout the configuration. For example, www.example.com has an IP address as 192.168.1.15. Rather than remembering the IP address of the intended website while accessing it, you can simply type www.example.com in the browser. The FQDN www.example.com will now be mapped to its respective IP address, and the intended webpage opens. 

    Thanks,

  • Hi H_Patel,

    H_Patel said:
    It is not advisable to delete predefined FQDN hosts, deleting them might cause some issues. If going through the long list is the issue, you might want to use search feature to sort required FQDN host.

    Is there a reason why it might cause some issues? As I know Sophos XG itself is using the defined DNS servers at Network > DNS to resolve hostnames.
    The FQDN hosts are just there for user specific rules, aren't they?
    Just want to go into the technical background here because it interests me a lot how XG firewall works. :)

    I'm not averse to using the search in the list, I just wanted to know why there are so much hosts predefined (this list seems to contain half the Internet... xD) when I never use them in any rule. If I need to allow specific services from providers (such as AWS or Google), I usually create these hosts myself.

    Cheers,
    Leon

    Intrusus
    Sophos Certified Engineer | Sophos Certified Technician

    private lab:
    XG firewall with SFOS 20.X running on Proxmox

    If a post solves your question use the 'Verify Answer' link

Reply
  • Hi H_Patel,

    H_Patel said:
    It is not advisable to delete predefined FQDN hosts, deleting them might cause some issues. If going through the long list is the issue, you might want to use search feature to sort required FQDN host.

    Is there a reason why it might cause some issues? As I know Sophos XG itself is using the defined DNS servers at Network > DNS to resolve hostnames.
    The FQDN hosts are just there for user specific rules, aren't they?
    Just want to go into the technical background here because it interests me a lot how XG firewall works. :)

    I'm not averse to using the search in the list, I just wanted to know why there are so much hosts predefined (this list seems to contain half the Internet... xD) when I never use them in any rule. If I need to allow specific services from providers (such as AWS or Google), I usually create these hosts myself.

    Cheers,
    Leon

    Intrusus
    Sophos Certified Engineer | Sophos Certified Technician

    private lab:
    XG firewall with SFOS 20.X running on Proxmox

    If a post solves your question use the 'Verify Answer' link

Children
No Data