This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to enforce local service ACL on Sophos xg v19.0.1 MR-1

Hi,

We are trying to implement local service ACL on LAN side but it's not working. After checking on community found multiple posts but none works. Below are the Drop all rule and ACL snaps:

Device Access:

Added another drop management portal (drop all) rule for testing purpose

ACL:

Tried to change source zone to LAN but that didn't solve the problem.



This thread was automatically locked due to age.
Parents
  • Hello there,

    The Local ACL doesn't need a Firewall Rule to work; they take precedence. 

    For your ACL exception rule, you shouldn't use #; only select ANY, and for Source Zone, select LAN and Services HTTPS.

    Ensure you’re also using Sophos Central to access your Device before making any ACL changes. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi,

    As I mentioned in my post, I have changed Source Zone from ANY to LAN and services are already HTTPS. What do you mean by the below point:

    Ensure you’re also using Sophos Central to access your Device before making any ACL changes. 

    FYI:

    • Firewall is not registered on Sophos Central
    • This is configured in Active-Passive Cluster. ACL is being configured on Active Device
  • Hello,

    I don't remember you mentioning anything in your post about changing the Source Zone to LAN.

    Have you changed the Destination Host?

    Accessing your Firewall via Central is the safest way to access from WAN. Since you’re going to be modifying your ACL rules, and you might lock out accidentally, it is good to have a "backdoor".

    All changes you made in your Active device will replicate automatically to your Passive device.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi Emmanuel,

    Thanks for sharing info on Sophos Central. I have not opened HTTPS access on WAN zone. Just trying to restrict access on LAN so that only specified IP's can access the Web Admin GUI. I've disabled HTTPS from Device Access on LAN Zone and, In My Local ACL Exception Rule:

    • Source Zone: LAN
    • Source Network/ Host: IPv4 Host
    • Destination Host: Lan Port
    • Services: HTTPS
    • Action: Accept

    Regards,

  • Hello,

    The information for Central was so you have a "backdoor" in case you lost access to your Firewall while configuring the ACL for the LAN.

    If the issue persists after the ACL is correct and you have confirmed the Source Network IP is correct too, run the following command from the console of the Sophos Firewall (SSH into the Sophos Firewall and press 4 > 3)

    console > show advanced-firewall

    And make sure you have nothing under Bypass Stateful Firewall

    Additionally, to this make sure the output of the following command is disabled

    console> system appliance_access show

    If this is enabled, run the following command to diable it

    console> system appliance_access disable

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello,

    The information for Central was so you have a "backdoor" in case you lost access to your Firewall while configuring the ACL for the LAN.

    If the issue persists after the ACL is correct and you have confirmed the Source Network IP is correct too, run the following command from the console of the Sophos Firewall (SSH into the Sophos Firewall and press 4 > 3)

    console > show advanced-firewall

    And make sure you have nothing under Bypass Stateful Firewall

    Additionally, to this make sure the output of the following command is disabled

    console> system appliance_access show

    If this is enabled, run the following command to diable it

    console> system appliance_access disable

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children