Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: [LetsEncrypt] How To in Sophos Firewall

Update: V21.0 supports Lets Encrypt onboard:  Sophos Firewall v21 Early Access Announcement  

Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.


NoteMake sure your Sophos Firewall time is correct to avoid potential Certificate Trust issues

Overview

This Recommended Read reviews different options for obtaining a Let's Encrypt certificate.

UTM has LE Support for WAF (since UTM9.6). But on Sophos, you can use LE certificates as well. Seems like many people does not know, you need a little Linux server and 5-10 minutes of your time each three month. Or you can automate this. 

First of all, I want to share the "how it works" page of LE. https://letsencrypt.org/how-it-works/

My Setup. 

Internet - Sophos - Ubuntu 20.04 LTS
Ubuntu has "certbot" installed. Feel free to use other LE modules.
https://certbot.eff.org/ https://certbot.eff.org/lets-encrypt/ubuntubionic-apache
Follow straight the Guide for your OS. I am relying fully on those apps for the renewal process.  

Next, I am choosing the HTTP-01 method for LE, so I need a DNAT for LE to my Ubuntu.

 (V18). 

PS: I am using HTTP DNAT for the renewal process and deactivate those Rules after the process. But you can also use only the LE IPs: 
https://community.letsencrypt.org/t/can-i-get-list-ip-from-letsencrypt/57117
PS2: You could switch to the DNS validation as explained in this Community thread.  

The next step would be to check your Domain. Your DNS A-Record should point to your WAN IP. Otherwise, this process won’t work. 
So perform a dig / nslookup of your domain. It’ll point to your WAN IP, so your DNAT will work, and HTTP packets will be forwarded to Certbot. 
You can also use the Sophos free DDNS service. https://community.sophos.com/kb/en-us/123126 

Certbot

Let us start Certbot and try it. 
My renewal process is straightforward:


(Be careful: LE blocks you after couple of "failed" requests for some time. So check everything).
Ultimately, you’ll get four files on your Linux: Public, Chain, Fullchain, Privatkey Certificates. 

Upload to Sophos Firewall

You’ll use this Public and Privatkey certificate. 
There are a couple of approaches to upload this to Sophos. 

The first LE Cert can be uploaded. 
You should use the Public.pem in "Certificate" and the Privatkey in "Privat key". 
PS: you have to rename the Privatkey.pem to Privatkey.key. Otherwise, Sophos won’t take this certificate. 

Optionally, you can upload the other Chain and fullchain Certificate under Certificate Authorities (Without Privat key). 
Now, you can use this Certificate for WAF/Webadmin. 

In case of renewal (each 90 Days), you have to choose a process.

Automation 

You can upload the new LE certificate with another Name and replace it in WAF/Webadmin. 
Or you can "update" the current LE certificate with the new public.pem / privat.key. But for this method, you have to switch to a fallback certificate in WAF/Webadmin, because Sophos can't update a currently used certificate.  

After all, those steps are manual processes every 90 Days. 
You can "script" this if you want to. So basically, upload the certificate every 90 Days to Sophos. 


Other members of the community have already performed scripts for this.

If you want to script this, this community can help you if you struggle with a point.
So please open a new thread with your issue with the API, and we’ll try to find a solution. 

Sophos Factory

Sophos Factory brings a new Tool to automate Script-based approaches. This means you can easily run a Script like Certbot or Lego in a Sophos Factory environment to generate and upload the certificate to the Sophos Firewall. 

Sophos Factory offers a free Community Edition. https://community.sophos.com/sophos-factory/ https://community.sophos.com/sophos-factory/b/release-notes-news/posts/get-started-here-sophos-factory-offer-automation-for-all-with-its-free-community-edition

Within Sophos Factory, it could look like this:

Each step is one scripting component.By using tools like Lego and Github, the "Pipeline" will run one time, generate the certificate and upload it to the Firewall. 

Contribution:
 
 https://zerossl.com/free-ssl/#crt Free alternative to this approach
For the Github script. 
 Thanks for the PHP Script! 
 for a Powershell Script with WAF integration. 
 for another version of a Powershell Script. 




Update.
[bearbeitet von: LuCar Toni um 7:48 AM (GMT -7) am 29 Aug 2024]
Parents Reply
  • Did you had a chance to look into Central Email, which brings all those features (plus additional features as well)? 

    UTM customers nowadays are advised to migrate to CEMA (Central Email) instead of using the Email Protection of the firewall.

    __________________________________________________________________________________________________________________

Children
  • Email Protection works pretty well I must admit. But its kind of annoying for my team to find reasons for undelivered mail as it is only visible as a tooltip. The use of rbl is very effective and made reports almost obsolet. 

    Glad LE finally made it to SFOS. 

    Still missing sophos otp for webserver protection though. :(

  • You could just say, our MTA implementation is crap - and we don't have plans to fix that -> use the cloud product instead.
    or move on to solutions that don't get crippled by their successor products.

  • Currently, all of my customers, when they get to choose between UTM and CEMA, they would go with CEMA all the way, as it is the full fetched email product, coming from the Sophos Email Appliance, which was always the primary Email product of Sophos. 

    Nowadays, as Sophos split up the email subscription into an own subscription, everybody can decide what to do with their email product and you are not locked into a bundle. 

    The promos of Sophos also include CEMA and not Email on the Firewall. 

    The Email protection of Sophos works as it is - and it does it job of scanning and filtering emails. Bugs are getting addressed and fixed as well.

    If a customer has certain requirements, you can always interact with Sophos or the Sophos partner to validate the options like moving to CEMA or interacting with another product. 

    __________________________________________________________________________________________________________________

  • might be a bit off-topic to continue with MTA in this topic...

    but moving to a cloud-based mail security solution when your emails are already in the cloud (e.g., EXO) makes (some) sense. However, relying on a cloud service to filter emails when you intentionally keep your mail servers on-premises to avoid data being on 'someone else's computer' (aka the cloud) is not just ironic—it's counterproductive and undermines the very reason for keeping things in-house. I'll keep the discussion about the Central Mail Product off this Thread.