This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Proxy allowing access from any net to internal (and otrher direction)

Hi,

we just got a little bit confused as we discovered that we can access our intranet (10.10.200.2 /16), http, from any of our other networks as GuestWlan (172.31.0.0/16), the DMZ (172.30.1.0 /24) and others if we call it by ip (http://10.10.200.2).

Other direction (internal to DMZ, Guest-WLAN to DMZ,...) also working.

The problem is, that the proxy is natting internal and even if the traffic is coming from 172.x to 10.x, sophos turns the sender IP to 10.10.1.1, the internal interface, so no firewall can capture and block this traffic. This was confirmed by sophos support.

But only 80, not 443 oder other ports that are allowed in Misc?
It's a proxy problem,no matter if standard or transparent proxy. If i turn of the Proxy WebFilter Profile for the source network, the problem is fixed.

So when I configure a Guest-WLAN with sophos as webproxy our guests can access our internal http sites.
I have 2 choices:
- a secure internal net and my guest can watch porn and do illegal stuff in my network (no proxy, only firewallrules)
- or my guests can enter our internal sites but are restricted to watch porn... (proxy and firewallrules)


I almost tested everything. Application Controll , explicit Drop rules for 80/http, proxysettings of the browser do not affect this problem.


Does anyone know this issue and has a better solution than blocking every single hostname and ip of the internal webservers?

I just found this discussion: https://community.sophos.com/utm-firewall/f/web-protection-web-filtering-application-visibility-control/45178/web-proxy-passing-port-80-to-internal-net-from-dmz
It seems logical to "use the Internet object instead of Any." - but where can I change this?




Greetings



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out, and welcome to the Sophos Community! 

    You probably have the web filtering policy configured to allow uncategorized websites, try to configure a new policy or update the existing policy for guest networks and block uncategorized websites.

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thanks for reaching out, and welcome to the Sophos Community! 

    You probably have the web filtering policy configured to allow uncategorized websites, try to configure a new policy or update the existing policy for guest networks and block uncategorized websites.

    Thanks,

Children
  • Thank you for that advise.
    Of course it's working, little bit better than blocking every single URL/IP but still only fighting symptoms.

  • Hallo Carina and welcome to the UTM Community!

    You might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, send me your email address via private message here.  Ich behaupte auch eine deutsche Version, die ursprünglich vom Mitglieder hallowach übersetzt wurde, als wir zusammen im Jahre 2013 eine große Revision machten.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    thank you very much. The document solved our problem.