<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>External Partners Accessing DMZ</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148015/external-partners-accessing-dmz</link><description>Hello, 
 
 Need your recommendations, we want to implement a SFTP server to exchange data from and to one of external partners. I am planning to add the server to DMZ group and just restrict FTP protocol to it. Create a NAT rule also i want to force the</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: External Partners Accessing DMZ</title><link>https://community.sophos.com/thread/548823?ContentTypeID=1</link><pubDate>Tue, 19 Nov 2024 11:48:19 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fe8f0ae3-6f8d-43d2-9eb9-af4481a154de</guid><dc:creator>Raphael Alganes</dc:creator><description>&lt;p&gt;Hello Reem,&lt;/p&gt;
&lt;p&gt;Good day, and thanks for reaching out.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Your proposed setup of clientless VPN should work since FTPS is supported on Clientless SSL VPN Bookmark:&amp;nbsp;&lt;a id="" href="https://docs.sophos.com/nsg/sophos-firewall/21.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/RemoteAccessVPN/Clientless/index.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/21.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/RemoteAccessVPN/Clientless/index.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I think the catches here are:&lt;/p&gt;
&lt;p&gt;-you do not have control over the end machine of the external partner (please take note of putting the server into a DMZ should the end machine has potential compromise)&lt;/p&gt;
&lt;p&gt;-clientless relies on HTTP/S to access resources and could potentially cause overhead&lt;/p&gt;
&lt;p&gt;-lacks further verification and access control, usually doesn&amp;#39;t put zero-trust model architecture into consideration etc.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Some Pros I can think are:&lt;/p&gt;
&lt;p&gt;-they are usually easy to implement and configure&lt;/p&gt;
&lt;p&gt;-suitable for yout external partners since they do not need to install anything and will just access the resource on demand&lt;/p&gt;
&lt;p&gt;That being said, the feature should work, but consider and weigh the items above (the list could go on, I only suggested essential ones I can quickly think of&amp;nbsp;&lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f642.svg" title="Slight smile"&gt;&amp;#x1f642;&lt;/span&gt;&amp;nbsp;)&lt;/p&gt;
&lt;p&gt;Further, I may recommend you as well to be in touch with your local Sophos Sales Engineer or Sophos Partner to discuss further your setup.&lt;/p&gt;
&lt;p&gt;I hope this helps you on your implementation.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>