DNS but how does it fit with Sophos other Products

Hello Sophos-Team,

as feedback to why to use Sophos DNS I do not understand:

- Transmission to Uplink DNS is not encrypted (DNS over HTTPS or DNS over TLS)

- DNS Validation is not done too DNSsec

The Current Products in the grand scheme of things are sufficient and already prove to be a challenge.

If your Infrastructure is protected by:

- Sophos XGS Firewall

- Sophos Intercept X Adv. with XDR (for Server too)

- And you setup your DNS Chain to best practice. (Client -> Firewall -> Domain Controller (or) Public DNS

The Sophos XGS Firewall does already have DNS request routing and does this fairly good and encourages Best Practice.

Now with all of the Products active you have three different Screens to worry about blocked content:

- Sophos Endpoint Protection (Web Control - SSL Inspection - Application Control)

- Sophos Firewall (Web Control Policy - SSL Inspection - Application Control)

This would make troubleshooting a mess if things are not centrally Controlled and Managed. What I mean to say is to be able to have one plane of glass that works with all of the great security solutions Provided. 

Plus atm DNS Querys are Super slow. ;)

Sincerely

Val.

Parents
  • Thanks very much for your feedback.

    Using secure transports is something that is on our roadmap after the release of version 1.

    The resolver does perform DNSSec validation. I'll reach out to you over DM if you're willing to give us a bit more detail of your concerns here.

    Managing all these products in Sophos Central gives us the opportunity to combine alerts over time. For example, the recent changes to the main navigation Central are just the first step in a range of improvements that will include customizable dashboards that will combine output from multiple products on a single screen. 

    DNS query response is mainly a factor of the location of our resolver services, which is still limited but which will expand by the time we reach the full release for the product.

  • Yeah sure I am happy to help. 

    The best part is that I have a complete homelab to play with and all is powered by Sophos. 

    Sophos Endpoint Security with XDR - Sophos XGS Firewall XStream Bundle with SSL-Inspection DPI Engine - For now I disabled DNS because the requests took quite some time but can reenable them in just a few min...

    All is connected with Sophos Central. ^^

    Sincerely

    Val.

Reply
  • Yeah sure I am happy to help. 

    The best part is that I have a complete homelab to play with and all is powered by Sophos. 

    Sophos Endpoint Security with XDR - Sophos XGS Firewall XStream Bundle with SSL-Inspection DPI Engine - For now I disabled DNS because the requests took quite some time but can reenable them in just a few min...

    All is connected with Sophos Central. ^^

    Sincerely

    Val.

Children
No Data