Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rules are not working

Good afternoon I have a problem that when I create a policy for firewalls and it is activated, it does not work. My goal is that I want to block access to the Internet, that is, so that when I go to some web page, my access is blocked, so that a message appears.

I work in Virtual Box, I have a Sophos server and a Windows 10 client. The goal is that when I log into Windows 10, all web pages are blocked. Now I will provide information in the form of screenshots to make it easier to understand the problem.


1. I made a NAT network that is shared. Sophos IP: 10.0.2.15/255.0.0.0:

2. In Windows 10 my IP is: 10.0.2.10

3. So I have a correct connection to the  Sophos server.

4. Then I went to the Sophos portal, logged in, and started creating a new policy in the firewall policy settings. I made it possible to connect from LAN to WAN. And assigned “Drop” to block access.

5. Here you can see that the policy has already been created and that it is activated. Her name is "Test".

6. If I go to Google, it doesn’t block my access

7. Also in Host and Services, I added Windows 10 IP, but it still doesn’t work for me.

I ask the Sophos Administration for help and will be grateful for any answer and help!



This thread was automatically locked due to age.
Parents
  • See second Screenshot - your Windows Client is not using your sophos as gateway (10.0.2.1 instead 10.0.2.15).
    Modify Gateway on Windows 10 or run tracert to see where routing goes...

  • What do I need to change? It seems that the website is correct: 10.0.2.1 for 10.0.2.15. Which one should I change it to?

  • When traffic from your Client to WAN should pass through your Sophos at 10.0.2.15 why is your default gateway on your client 10.0.2.1.

    Traffic to WAN would be sent to 10.0.2.1 which seems to be not your sophos? So sophos would not be able to filter anything…

    Simply go to your clients network adapter settings and change gateway from 10.0.2.1 to 10.0.2.15!

Reply
  • When traffic from your Client to WAN should pass through your Sophos at 10.0.2.15 why is your default gateway on your client 10.0.2.1.

    Traffic to WAN would be sent to 10.0.2.1 which seems to be not your sophos? So sophos would not be able to filter anything…

    Simply go to your clients network adapter settings and change gateway from 10.0.2.1 to 10.0.2.15!

Children