Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Proxy from WAN

My scenario has 2 separate locations that are connected by tunnels over the internet with one network using the tunnel interface of the router in the other network as the default gateway.  The plan is to have the 2 locations use the same web proxy.  I have setup Sophos XG firewall to be a web proxy in gateway mode on one LAN using this article: https://community.sophos.com/kb/en-us/125585 and it is working as expected .  Then I setup a DNAT firewall rule to allow access to the web proxy from the WAN .  I can ping the LAN interface of the Firewall from the remote network but in the log viewer I am getting Denied messages for the connections to the web proxy from the remote network.

 Is what I am trying to do possible with the Sophos XG firewall?  I realise that the Web Proxy is disabled for the WAN zone in Administration->Device Access but I have little knowledge in dealing with firewalls to know if I am on the right path or I should quit.

 



This thread was automatically locked due to age.
  • Tich,

    allowing web proxy from WAN zone is risky and that's why XG does not allow to enable it (public users can use your XG to proxy traffic and consume your bandwidth and resouces).

    You should establish a VPN between the 2 sites and allow web proxy on VPN zone.

    Regards