Hi every body/
I'm no familiar with XG so much (I have UTM).
Is it possible to configure rules in firewall in XG to use "user" or "user group"?
The XG gets the user list thru active director.
My goal is to create a firewall rule based on users group object (Not IP).
hop It's clear
Thanks Goldy.
Hello Goldy_01 ,
Thank you for reaching out to the community, please refer the following KBA _ user-based firewall rules - https://support.sophos.com/support/s/article/KB-000035564?language=en_US#
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hi and thanks.
will it work WITHOUT intercept X?
I use another AV.
There are various authentication method, if you do not have intercept X then you can opt for another auth method , like captive portal or SSO, agent, NTML or Radius/AD SSO
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Ensure the rule is on the top
Can you perform a packet capture - https://support.sophos.com/support/s/article/KB-000035761?language=en_US
And confirm with the help of packet capture !
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
You are currently trying to allow traffic based on a DNS Name, which is more likely a CDN based URL.
So you should first check the live users, if your use is authenticated. If not, go back to the steps mentioned above: https://support.sophos.com/support/s/article/KB-000035564?language=en_US The firewall needs to know the IP based on your User.
Then you should create a LAN to WAN Rule with ANY Service and your user.
Then you should enable the web proxy in the firewall rule, within the webfilter you can allow/deny based on user groups.
__________________________________________________________________________________________________________________
Hi Toni.
Thanks.
We have been told by Sophos supporter that for using Packet filter with "User" object, user must have a Sophos interceptX install on his workstation.
Is it so, or can we go by without it.
Regards,
Goldy
So - The firewall can use the user information provided by one of the listed above. The easiest way to implement is the endpoint itself, but it is not limited to only the endpoint.
Most commonly used (if not using the endpoint) is stas. https://docs.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Authentication/HowToArticles/AuthenticationConfigureTransparentAuthenticationSTAS/index.html
You can use this tool to extract and implement authentication with the firewall on your AD server.
__________________________________________________________________________________________________________________
Hi Toni.
If I understand you correctly, you talking about web filtering, while I'm talking about packet filtering (Firewall).