<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Access with broadcast IP address</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/132670/access-with-broadcast-ip-address</link><description>hello, 
 we have SG330 (SFOS 18.5.2 MR-2-Build380 ) , and we discover that we can access the firewall with broadcast address, how we can desactivate it . 
 any help 
 thanks</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/489312?ContentTypeID=1</link><pubDate>Thu, 17 Feb 2022 18:12:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:884d6f9f-3f6a-4d0c-be83-625dd730bc03</guid><dc:creator>emmosophos</dc:creator><description>&lt;p&gt;Hello there,&lt;/p&gt;
&lt;p&gt;I have sent you a PM.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/489283?ContentTypeID=1</link><pubDate>Thu, 17 Feb 2022 11:40:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:81aa1010-9f61-4199-9185-60304680056b</guid><dc:creator>minis</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Thank you for your response&lt;/p&gt;
&lt;p&gt;I check the config , but I didn&amp;#39;t any overlapping between&amp;nbsp; VPN and LAN network .&lt;/p&gt;
&lt;p&gt;NB: Just to clatify I did the test from VPN network .&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Best regards ,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/489126?ContentTypeID=1</link><pubDate>Tue, 15 Feb 2022 16:53:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:bf1a535d-336d-4aaa-9fdc-20e87e764b97</guid><dc:creator>emmosophos</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Thank you for the screenshot.&lt;/p&gt;
&lt;p&gt;Please take a screenshot of your interfaces, only fade the Public IPs, not need to fade the internal ones, and also take a screenshot of your SSL VPN &amp;quot;Show VPN settings&amp;quot; it looks your range is overlapping with your subnet as the traffic you&amp;rsquo;re mentioning is coming from tun0 interface.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/489104?ContentTypeID=1</link><pubDate>Tue, 15 Feb 2022 11:03:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:867081d3-d7f9-4020-8cf8-523ac82c4856</guid><dc:creator>minis</dc:creator><description>&lt;p&gt;hello;&lt;/p&gt;
&lt;p&gt;bellow the output of the cmd&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1644926573937v1.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488787?ContentTypeID=1</link><pubDate>Thu, 10 Feb 2022 23:53:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:970f6213-8065-4c01-93c1-81ea5dea5709</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;More than likely you have a network mask allowing the 255 address to be valid somewhere your configuration eg /23.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488763?ContentTypeID=1</link><pubDate>Thu, 10 Feb 2022 20:06:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a083730d-921e-4d51-9c05-f8b29e4443d9</guid><dc:creator>emmosophos</dc:creator><description>&lt;p&gt;Hello there,&lt;/p&gt;
&lt;p&gt;Most likely you have a bypass of the Firewall.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;SSH into the XG and run the following command from the Advanced Shell:&lt;/p&gt;
&lt;p&gt;# cish&lt;br /&gt;console&amp;gt; show advanced-firewall&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488735?ContentTypeID=1</link><pubDate>Thu, 10 Feb 2022 14:14:21 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:62a761ef-87a0-4789-9ae0-1fc2293b94fe</guid><dc:creator>minis</dc:creator><description>&lt;p&gt;Hi ,&lt;/p&gt;
&lt;p&gt;hereafter the interface configuration &lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1644505679387v2.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;the access to the broadcast address&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1644505575184v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;the logs show the traffic is dropped, however, access is allowed&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1644505958826v7.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;any idea !!!&lt;/p&gt;
&lt;p&gt;BR,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488654?ContentTypeID=1</link><pubDate>Wed, 09 Feb 2022 21:29:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1e818e31-597e-4aea-9abc-2b834d247798</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;please post a logviewer entry showing this and also your network interface configuration in expanded form with critical information blocked out.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488599?ContentTypeID=1</link><pubDate>Wed, 09 Feb 2022 11:22:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8ed7df2f-fcba-4f4f-bfea-f96a7adabdf8</guid><dc:creator>minis</dc:creator><description>&lt;p&gt;hi,&lt;/p&gt;
&lt;p&gt;you are right, we can access it with our local broadcast IP address . and we don&amp;#39;t have any access related to this access,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;we allow access with administration &amp;gt; device access&amp;nbsp;&lt;/p&gt;
&lt;p&gt;any advice !!!&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access with broadcast IP address</title><link>https://community.sophos.com/thread/488597?ContentTypeID=1</link><pubDate>Wed, 09 Feb 2022 11:08:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:08f28488-c408-46f0-a320-a2ceda490e5d</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I assume you are talking about 10.10.10.255:4444 in a /24 network? &amp;nbsp;Please post the log entries showing this and then the firewall rule being used?&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>