Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Server Protection XGS

Dear All

I currently setup new lab to test Web Server Protection at XGS firewall.

My setup:

1. Web Server using Xampp (LAN Zone) - IP: 192.168.100.2

2. Virtual Firewall XGS. (LAN Interface IP: 192.168.100.254) ( WAN Interface IP: 192.168.43.59)

3. PC to access Web server (WAN Zone) - IP: 192.168.43.17

I already define Web Server which follow this manual

1. https://docs.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/WebServer/WebServers/index.html


2. https://docs.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/WebServerProtection/WAF/Rules/WAFRuleAdd/index.html

But after the configuration is complete. I try to access the Web Server but the error show is 403 Forbidden.

May i know is there any config that i overlook or mistake that i made?.

Please Help.

Thank you



This thread was automatically locked due to age.
Parents
  • Seems "forbidden" is the answer from your webserver ... check the log-viewer / web-server-protection.

    May be, you have to set "pass host header" ... or not or some other WAF options.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • Seems "forbidden" is the answer from your webserver ... check the log-viewer / web-server-protection.

    May be, you have to set "pass host header" ... or not or some other WAF options.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children