This is a pretty newbie level question.
I previously had two websites set up behind a Sophos XG CE firewall using Let's Encrypt on the webserver. (Ubuntu 22.04 Apache). Under this configuration I had redirect HTTP to HTTPS enabled on the WAF, and the Sophos would communicate to the back end server over HTTPS and everything was working well. It was a pain to have to manually copy the Let's Encrypt certs to the XG firewall every 90 days, but so be it.
With v21, I have successfully set up Let's encrypt on the firewall. My question though is, under this new setup, I'm guessing I need to now reconfigure my Apache server to only accept HTTP, and only accept traffic from the firewall? The XG terminates HTTPS and then communicates with the webserver unencrypted?
If not I'm struggling to understand what the let's encrypt on the firewall gives you? Or does this mean I can use a self-signed cert for the XG to Webserver traffic now? Or will that also not work? I guess I'm just trying to understand what the best practice is here when using Lets Encrypt on the firewall itself.
This is for a home lab which also runs my band's website. The server is in an isolated vlan with all external traffic having to go through the WAF, so I'm thinking it's relatively safe to have the XG to web server communication be unencrypted?
I'm an idiot. It didn't occur to me you could still use Let's Encrypt on the protected server as well as on the Firewall at the same time. Disregard.
Hi Craig Glaser The blog post below summarizes these new features and their benefits.
Sophos Firewall v21: Let’s Encrypt certificates
news.sophos.com/.../
Let´s Encrypt Deep Dive & Debugging in SFOSv21.0
community.sophos.com/.../let-s-encrypt-deep-dive-debugging-in-sfosv21-0
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.