This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Access to webserver (VPS): http://vcTerminal.company.com:9595

Hi all,

I have xg firewall

i can't access to this vps (in object)

i just firstly make firewall rule:

source zone:lan

destination zone: wan

networks source: Any

network destination: any

services: http

web policy: url list with only "">vTerminal.company.com:9595"

I think it's incorrect

I tested also:

source zone:lan

destination zone: wan

networks source: Any

network destination: any

services: http, Port-9595 ( with value-9595)

web policy: url list with only "">http://vTerminal.company.com"

nothing !

I think ( not tested yet), the correct rule is:

source zone:lan

destination zone: wan

networks source: Any

network destination: public ip @ 

services: http,Port-9595 ( with value-9595)

web policy: All

Really i don't know how to combine that in firewall rule !?

can you help me to resolve this

Thanks



This thread was automatically locked due to age.
Parents
  • Hi Fotit,

    Thank you for reaching out to Sophos Community.

    If you had tested out the Rule

    Source: LAN - Destination ANY, Services HTTP/ Port, and it’s still not working.

    Kindly check the log viewer(packet capture, TCPDump, Conntrack) as to what has happened to the traffic. 

    Where it was dropped or blocked.

    Check if it has gone out of your Firewall

    Does it go out on the correct WAN interface etc

    Or create an FW rule on the very top with a single IP for the source ( for security ) and allow all access (Destination, Services ) to ANY, then checked the traffic logs

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Erick, thanks for your help

    Before to do the troubleshooting, can you tell me the correct rule for this traffic please. I want to make sure the rule is correct

    VPS--> http://vcTerminal.company.com:9595

    source zone:lan

    destination zone: wan

    networks source: Any

    network destination: ??

    services: ??

    web policy: ??

  • Hi Fotit,

    You may define the network destination/create to vcTerminal.company.com( IP address). You can check by pinging

    services: 9595

    Web Policy: Don't use one first for testing

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Reply Children