Hi all,
I have 2 different wan connections with different ISP and IP addresses connected to xgs 118.
Is there a way to send this 2 wan port connections to the syslog server ?
I can only send one of them.
Is there any way to configure like;
or
To the same file.
Hello,
Are you referring syslog server as mentioned in KBA? docs.sophos.com/.../index.html
Are you having two different syslog server or one?
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello Makvana,
2 wan connections, 1 syslog server.
Here is setup of syslog mngmt page;
Hello,
Thank you for sharing the details.
If there is no SD-WAN or static route defined, the traffic will be sent through the WAN link manager, which means it may route the traffic through any random WAN interface.
Unfortunately, we cannot send traffic through both interfaces simultaneously. However, you can define an SD-WAN or static route to direct the traffic through a specific interface of your choice.
You may refer to the below KBA to configure SDWAN route for the system generated traffic.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thank you Makwana,
Does the device send the activity of the 2 wan connections in the log files it transmits?
Hello,
Yes, it does include the details of all the connected interfaces.
Are you looking for any specific details of WAN2? or are you unable to capture anything for WAN2?
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thank you Makvana,
I need 2 wan port activities to be sent to the syslog server not necessary to be separated.
We cannot determine which wan port the device uses when sending the activity logs to the syslog server.
This is an issue for us because we make the server settings according to these wan ips (listening from ip:port)
Hello,
Certainly, for that either you can define static route or SDWAN route for Syslog server. The KBA shared above for the configuration may help.
Or you can DM me if any doubts.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thanks alot.
I created a rule for syslog server domain via Routing table. Now i can select which wan port to be used when sending data to the syslog (Link selection settings > Select SD-WAN profile Primary and Backup gateways).
It works now as we intended.
Is there a way changing the default behaviour of the machine ?
Trying to solve my issue without special routing configuration.
Hello Can carmack
Thank you for the update. I am glad to hear that you managed to configure and get it working.
We cannot change the WAN link manager behavior. We need to get this working with this configuration and its widely accepted.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.