Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Web Server Protection not working

Hi All,

Sorry if this has been asked previously, I have combed through the forums and could not find a solution or direct discussion to this specific issue I am facing.

We have signed up for the Sophos XG Firewall via the Azure marketplace image.
I am not too experienced in configuring Sophos firewall, but I have accomplished the basic setup of the firewall with forums & how-to's.

My next step was to protect my WebServer with the Web Server Protection Rule.

When I set the rule as follow:

The first error I get is a dependency error. so my rule sometimes doesn't enable, but it's erratic, sometimes it's on sometimes off.

When my rule is in effect I get the below 503 error.

My site works when I remove the Wep protection rule and allow HTTP & HTTPS via a standard firewall rule & NAT Rule.

I looked at all the how-to's and videos I could find online.
I have a few questions about this if possible:

  1. I have added a web server under hosts and can confirm networking is in order, I know this works by the fact that I can RDP into the server, and the session remains open for hours even when I make other changes to the firewall rules, why does the web protection rule keep saying there is a dependency error, and if there is how do I fix this?
  2. When creating this Web Protection Rule, do I need to create a NAT rule that runs side by side with the Web Protection Firewall Rule? And if so how do I do this as all documents only point to one Rule and no additional NAT rules?
  3. My web server is configured to redirect HTTP to HTTPS on the server itself, my wildcard certificates are installed on the web server and the Sophos firewall, as mentioned earlier when allowing HTTP & HTTPS as a basic firewall rule, my site works fine.

As mentioned I have the Sophos XG Firewall licensed via Azure Marketplace for my cloud environment and can confirm my licensing is in order.

Any Support would be greatly appreciated.

Regards



Edited TAGs
[edited by: Erick Jan at 9:26 AM (GMT -7) on 29 Jul 2024]
Parents Reply Children
No Data