Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: Using Firewall "Rule Groups"

Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.


Table of Contents

Applies to:

All Sophos Firewall (XGS, Virtual, Software, Azure, AWS) Firmware v18.0+

Configuration:

Sophos Firewall > Admin UI > Protect>Rules and Policies > 

Steps:

  1. As shown in "Where do I configure this?" you’ll log into your Firewall via HTTPS//172.16.16.16:4444 or MGMT interface
  2. Select "Protect: Rules and Policies" in the left menu, then Add Firewall Rule.
  3. Within the Add Firewall Window, you’ll see the following. Open the drop-down menu on "Rule Group":
  4. Click Add to add a new Rule group that will automatically put all firewall rules we have to create now and in the future into a "LAN-to-WAN" Rule Group. 
  5. Give your new "Rule Group" an appropriate name based on the targeted Firewall Rules. In this example, I have named it "LAN-to-WAN" and described other admins and myself when reviewing it later.
  6. Continuing down the window, we will now specify our Group Matching Criteria
  7. After creating this rule, you will return to the previous firewall creation menu and notice that you have a Rule Group selection of "LAN-to-WAN."
  8. From here on out, whenever you create a firewall rule with this matching criteria, you can leave the Rule Group selection as "Automatic," which will place the rule into the appropriate Rule Groups.
  9. Rule Groups are often seen to be effective:
    1. LAN-to-WAN (Group internet Traffic Rules)
    2. LAN-to-LAN
    3. LAN-to-DMZ
    4. DMZ-to-LAN 
    5. LAN-to-VPN
    6. VPN-to-LAN
    7. WAN-to-LAN
  10. You can also refer to this Documentation for creating Firewall Rules
    1. Add a firewall rule - Sophos Firewall




Revamped RR
[edited by: Erick Jan at 9:03 AM (GMT -7) on 18 Sep 2024]
Parents Reply Children
No Data