<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Local service ACL exception rule command line?</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/132584/local-service-acl-exception-rule-command-line</link><description>I enabled the Local service ACL exception rule. Some how, I didn&amp;#39;t get that right. Now im locked out from Web interface. The SSH is still working. 
 How can i disable this ACL from command line/SSH? I tried: 
 console&amp;gt; system appliance_access show Appliance</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Local service ACL exception rule command line?</title><link>https://community.sophos.com/thread/488232?ContentTypeID=1</link><pubDate>Sat, 05 Feb 2022 08:32:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:66a1fd7d-cd13-4e8c-b97c-c6ff0c425705</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/eirik-jolle"&gt;Eirik Jolle&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Please follow the below steps to meet your requirement :&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;1. Execute the below command :&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;console&amp;gt; system appliance_access enable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;2. Now access the Sophos XG firewall GUI, as per the above command you will get on HTTPS SSH ping and all the services available on Sophos XG&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;3. Enable the HTTPS from Sophos XG GUI Webadmin and the service/s you have to disable previously.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;4.&lt;/span&gt;&lt;span&gt;&amp;nbsp;Execute the below command :&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;console&amp;gt; system appliance_access disable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;5.&lt;/span&gt;&lt;span&gt;Go to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;&lt;span&gt;Administration&lt;/span&gt;&lt;abbr&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/abbr&gt;&lt;span&gt;Device access&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;and click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Add&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;under&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Local service ACL exception rule&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;Enter a name.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Select the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Rule position&lt;/span&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Enter a description.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Select the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;IP version&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;from the following options:&lt;/span&gt;
&lt;div&gt;Available options:
&lt;ul&gt;
&lt;li&gt;IPv4&lt;/li&gt;
&lt;li&gt;IPv6&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Select the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Source zone&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to which the rule applies.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Add new item&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to select source hosts (based on a network, IP address, range, or list) to which the rule applies. Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Create new&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to create a new source network/host.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Add new item&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to select the IP address or interface-based destination hosts (example: user portal) to which the rule applies. Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Create new&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to create a new destination network/host.&lt;/span&gt;
&lt;div&gt;
&lt;div&gt;&lt;span&gt;Note&lt;/span&gt;Specifying the destination host enables you to control access to a service (example: user portal) with a limited set of destination IP addresses.&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Add new item&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to select the admin&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Services&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to which the rule applies.&lt;/span&gt;
&lt;div&gt;Available options:
&lt;ul&gt;
&lt;li&gt;HTTPS&lt;/li&gt;
&lt;li&gt;Telnet&lt;/li&gt;
&lt;li&gt;SSH&lt;/li&gt;
&lt;li&gt;Web proxy&lt;/li&gt;
&lt;li&gt;DNS&lt;/li&gt;
&lt;li&gt;Ping/Ping6&lt;/li&gt;
&lt;li&gt;SSL VPN&lt;/li&gt;
&lt;li&gt;User portal&lt;/li&gt;
&lt;li&gt;Dynamic routing&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Select an&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Action&lt;/span&gt;.&lt;/span&gt;
&lt;div&gt;
&lt;div&gt;Available options:
&lt;ul&gt;
&lt;li&gt;Accept&lt;/li&gt;
&lt;li&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;Save&lt;/span&gt;.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;11. Refer the below snapshot :&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1644049659243v1.png" alt=" " /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1644049793530v2.png" alt=" " /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;12. After you create the rule as above only those IP mentioned on Source Network/host will have access to Sophos XG.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;13. You can manage Sophos XG firewall from Sophos Central free-tail is available by Sophos.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Local service ACL exception rule command line?</title><link>https://community.sophos.com/thread/488218?ContentTypeID=1</link><pubDate>Sat, 05 Feb 2022 00:04:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c57477df-1c49-4d88-a790-6a1437680b41</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Actually that should give you access back on all interfaces.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>