<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148040/waf-with-the-webserver-hosted-in-azure</link><description>Hello, 
 
 we have a VPN-tunnel from our XG330 (SFOS 20.0.2 MR-2) to Azure and want to host a web application in azure. 
 The VPN Tunnel was done via the configuration file and is route based, with the xfrm interfaces being in the169.254.0.0/30 subnet</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/thread/549269?ContentTypeID=1</link><pubDate>Tue, 03 Dec 2024 09:00:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7d591eb4-c9c3-4a88-8797-327d814daf27</guid><dc:creator>Dominik Friedl</dc:creator><description>&lt;p&gt;Thank you for the info! We will see if we can make it work with routing on the Azure side. Unfortunately, policy-based is no option for us. We have tried this before and had a lot of troubles with the tunnel disconnecting.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/thread/549130?ContentTypeID=1</link><pubDate>Wed, 27 Nov 2024 14:42:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1c17266a-7bde-4366-82de-847d03e587e1</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/dominik-friedl"&gt;Dominik Friedl&lt;/a&gt;&amp;nbsp;, I have verified WAF over Policy based IPsec VPN on XGS---Azure&amp;nbsp;setup, it works for me..I see LAN port&amp;#39;s ip is being used for&amp;nbsp;system generated TCP packet from SFOS and the web server page is loaded on the client&amp;nbsp;requesting&amp;nbsp;web page.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/thread/549115?ContentTypeID=1</link><pubDate>Wed, 27 Nov 2024 07:21:13 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:addbb840-6fa3-4f70-adb1-6745c29f3b6c</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;Hi @&lt;a href="/members/dominik-friedl"&gt;Dominik Friedl&lt;/a&gt;, sys-traffic-nat on cli of SFOS will not help placing waf traffic with the&amp;nbsp;configured ip; in case of waf&amp;nbsp;with route based vpn, the source ip will always be the xfrm ip. Please try if your use case with Azure works with policy based VPN, this uses one of the LAN ports ip while placing waf traffic into IPsec tunnel.&lt;/p&gt;
&lt;p&gt;If the usage of route based vpn is a must, then please check with Azure on the routing part.&lt;/p&gt;
&lt;p&gt;Also, if it is fine to use without WAF rule, equivalent functionality can be achieved by using SANT and DANT rules on SFOS.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/thread/549077?ContentTypeID=1</link><pubDate>Tue, 26 Nov 2024 08:28:59 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:050801e9-48e1-4297-84e8-88c7de63b531</guid><dc:creator>Dominik Friedl</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I have screenshots attached from the tests. 10.25.0.100 is the webserver.&lt;/p&gt;
&lt;p&gt;First test was a ping with the SNAT for system-generated traffic:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/6646.showAdvancedFirewall.png" /&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pingOnFirewall.png" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pcapPingOnFirewall.png" /&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/tcpdumpPingOnFirewall.png" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Then I tried to access the WAF from my client:&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/tcpdumpAccessWAF.png" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pcapAccessWAF.png" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/126356/sophos-firewall-configuring-an-ipsec-vpn-gateway-connection-to-azure"&gt;Sophos Firewall: Configuring an IPsec VPN Gateway Connection to Azure&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;I used this instruction to setup my VPN Tunnel.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF with the webserver hosted in Azure</title><link>https://community.sophos.com/thread/548863?ContentTypeID=1</link><pubDate>Wed, 20 Nov 2024 17:04:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:babc35f9-2dd7-400b-bb4c-be03655c7b55</guid><dc:creator>Hardik_R</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/dominik-friedl"&gt;Dominik Friedl&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;you are&amp;nbsp;following the right way however TCPDUMP &amp;amp; GUI packet capture(Diagnostics &amp;gt; Packet capture) output for below 2 situations will help to understand more on packet flow :&amp;nbsp;tcpdump -nei any host &amp;lt;web server IP&amp;gt;&lt;/p&gt;
&lt;p&gt;1. When you ping the webserver directly from the firewall.&lt;br /&gt;2. When you try to access web server using WAF&lt;/p&gt;
&lt;p&gt;Also&amp;nbsp;Which IP you have used in SNAT for system-generated traffic? and after configuring this, are you getting ping reply?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>