Sending Syslog and NETFLOW to a external FLOW and Logging server that is in Azure.
The device shows up as the IP address of the Azure Tunnel (which is on the WAN Interface) not as the Management Interface of the Sophos.
Need to change the source interface of both services. The other issue is I have four Sophos with Azure VPNs and all four are showing the same IP address.
Should be possible with the CISH command: Try: https://support.sophos.com/support/s/article/KB-000035607?language=en_US
If this does not work, try a SD-WAN Route instead. In SD-WAN use ANY - ANY and Service…
Bump, anyone know a way to source services from a different interface? Especially with Servers that are in Azure?
If this does not work, try a SD-WAN Route instead. In SD-WAN use ANY - ANY and Service: Syslog.
Thanks LuCar, the CISH command worked perfectly!