<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPS with webproxy/MTA/WAF</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/123753/ips-with-webproxy-mta-waf</link><description>Hi all, 
 I&amp;#39;m testing XG firewall as home user now in a side role (proxy) before putting it in as router. I have now v18.0.3. 
 I could not find answers to question below. 
 If IPS (Application Control) is configured in FW policy, does it work for: 
</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPS with webproxy/MTA/WAF</title><link>https://community.sophos.com/thread/451397?ContentTypeID=1</link><pubDate>Sat, 31 Oct 2020 12:45:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9b7e283b-2a8d-4a8c-9e7a-43b5ed13fd42</guid><dc:creator>Tomas Beran</dc:creator><description>&lt;p&gt;Hello Emmanuel,&lt;/p&gt;
&lt;p&gt;thanks for feedback.&lt;/p&gt;
&lt;p&gt;I did a test with webproxy when it is configured in browser (NO transparent).&lt;br /&gt;The IPS seems to be triggered on http cleartext traffic.&lt;br /&gt;But IPS does not trigger for HTTPS traffic even if it is decrypted by webproxy.&lt;/p&gt;
&lt;p&gt;So my conclusion is:&lt;br /&gt;1. IPS is applied to traffic passing through IPS engine to webproxy port. With HTTPS it sees only the SSL/TLS stream.&lt;br /&gt;2. the decrypted cleartext traffic by webproxy in this scenario is not scanned by IPS itself -&amp;gt; no reason to enable it if most traffic is HTTPS and in this case it does not protect clients&lt;br /&gt;3. probably the same for Application contorol&lt;/p&gt;
&lt;p&gt;I would expect that the same is for WAF if all traffic is https. IPS can see only SSL/TLS stream, but can&amp;#39;t see the inner clear text traffic to protect for example vulnerabilities in web server etc.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS with webproxy/MTA/WAF</title><link>https://community.sophos.com/thread/451364?ContentTypeID=1</link><pubDate>Fri, 30 Oct 2020 22:43:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e4835c9f-01a5-479e-b055-7a8a6371e761</guid><dc:creator>emmosophos</dc:creator><description>&lt;p&gt;Hello Tomas,&lt;/p&gt;
&lt;p&gt;Thank you for contacting the Sophos Community!&lt;/p&gt;
&lt;p&gt;Yes, IPS will work for Web Proxy, MTA and WAF Traffic.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>