Hello
Is it possible to use a group of IP addresses in a WAF rule exception? Adding many IP hosts one by one is very cumbersome.
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
Hello
Is it possible to use a group of IP addresses in a WAF rule exception? Adding many IP hosts one by one is very cumbersome.
Hello there,
Good day and thanks for reaching out to Sophos Community and hope you are well
Yes you can create IP address group on exceptions via IP range and IP list options
Hope this helps. Have a nice day and thank you for choosing Sophos.
Cheers,
Raphael Alganes
Community Support Engineer | Sophos Technical Support
Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'Verify Answer' link.
Hello there,
Good day and thanks for reaching out to Sophos Community and hope you are well
Yes you can create IP address group on exceptions via IP range and IP list options
Hope this helps. Have a nice day and thank you for choosing Sophos.
Cheers,
Raphael Alganes
Community Support Engineer | Sophos Technical Support
Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'Verify Answer' link.
When i try add exception it looks like this:
I can select only IP host or Network.
Hello there,
Kindly click on IP Host and options should expand and you can select type of IP as on the screenshot above.
Cheers,
Raphael Alganes
Community Support Engineer | Sophos Technical Support
Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'Verify Answer' link.
But I want to select a group from Hosts and Services -> IP Host Group. This will allow me to add another IP address without updating multiple WAF policies.
Hello there,
Adding to what Raphael has mentioned.
After you click Add > IP Host > A new Window will pop-up that will allow you to select an IP Host Group.
Regards,
Nope, you are creating group and adding host to this group. I want group (created in System -> System and services -> IP host group) to be added to WAF exception instead of single ip host. It is imossible as i see. You can add only single host or network one by one, not group of IP hosts. IP host groups can be added to firewall policy (but not WAF).
Hello,
This would be a Feature Request, I'd recommend you to reach out to your Account Manager, Sales Engineer or Sales Representative so that they can enter this request into our system.
Additionally, you can use the in-product feedback in the Sophos Firewall located in the Top Menu Bar.
Regards,