Hi,
With SophoSG, it was possible to use objects (host, subnet, etc.) in static routes.
In XGS, this is no longer possible.
SDWAN routes and gateways should solve this problem. But this is not possible for 2 reasons:
- Case 07078419: if you create an SDWAN route to a supercope (e.g. 10.0.0.0/8), it overwrites directly connected networks. So you have to use a simple static route.
- If SD-WAN route is set before static route, a matching SD-WAN route is applied to directly connected network traffic. Static routes include directly connected networks.
- Change the route precedence placing static route before SD-WAN route on the CLI.
- https://doc.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Routing/SDWANPolicyRouting/RoutingSDWANPolicyRoutingTroubleshooting/index.html#routing-and-connection-issues
- Case 04648590 : If you route via SDWAN, IPSpoofing blocks traffic from unknown networks. Static routes are therefore required.
- SD-WAN configurations are not routes, are just like firewall rules, so that they support objects and services.
- Routes are instead restricted to the networks and this information is used by Spoof Protection as well: if the route is configured to interface Port1 and the packet arrives on Port1 it's fine, otherwise it will be blocked.
- I understand that the learning curve could be different on XG, but the support of objects in the static route configuration has to be considered as a feature request.
- You can instead consider the routes as a lower layer and the SD_WAN policy as an upprer layer in case you have multiple routes to the same destination (for routing decision based on preference).
- You can also use SD_WAN without any route, but in this case Spoof protection checks are not satisfied.
It would be preferable to be able to use either :
- Solution A : SDWAN routes instead of static routes (to take advantage of objects (gateway and network, host,...) )
- Solution B : Objects (gateway and network, host, etc.) in static routes.
Nice to have your feedback on this subject.
Thomas
This thread was automatically locked due to age.