This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Nur den SSL-Client für Ingternetzugriff zulassen, den restlichen Verkehr sperren

Hallo zusammen,


ich setze bei uns 2 VPN-Lösungen ein. Zum Einen den PPTP-Client (Windows integriert) und den Sophos SSL-Client.

Beim PPTP-Client wird automatisch am Client der restliche Verkehr Richtung Internet geblockt, beim SSL-Client zugelassen.

Gibt es eine Möglichkeit den SSL-Client so zu konfigurieren dass der Verkehr wie bei PPTP-Client geblockt wird?




This thread was automatically locked due to age.
  • If you want to completely block internet traffic for the SSL-VPN client you can include Internet IPv4 and/or IPv6 in your VPN local networks configuration so all traffic outside the local LAN from this VPN-client is sent to the UTM. Then you can make a firewall rule to allow what needs to be accessed and make sure auto firewall rule for the SSL VPN is not enabled. Also you might not want to have a masquerading rule for SSL pool => External. You would also leave SSL pool from the web filtering allowed networks so they also cannot use the proxy for web browsing. In that case all traffic is sent to UTM but internet traffic is dropped.

    If you do want internet access but you want it controlled and checked by the UTM also include Internet IPv4 and/or IPv6 in the VPN local networks so all traffic is again sent to the UTM. Then either use the VPN pool to the allowed networks for web filtering to allow usage of the web filter (and/or configure a masquerading rule for VPN pool => External for direct access to the internet through the UTM).

    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • "you can include Internet IPv4 and/or IPv6 in your VPN local networks configuration"

    and how can i do that?

Reply Children