This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Basic Question(s)

I am a recently hired Network Specialist (paid intern really) and have been tasked with figuring out how to install Sophos UTM onto a VM setup under Windows Server 2012. I have read through the installation guide on how to do that and it all seems pretty straight forward. I am however confused on where its supposed to sit on my network, and I have no one with that expertise/knowledge here to ask, so hopefully someone can be of some assistance as to what the best practice is.

I'm still trying to map out our network devices but so far I'm able to tell were using a Cisco ASA (5500 series I believe) router that's acting as our firewall and then it goes pretty much straight into our network. What I've read about the setup and after watching some of the "using sophos utm" videos it looks like the UTM can replace our router or at least handles a lot of the same functions, could this be a correct assessment? I am fairly certain it handles all of the firewall rules and filtering but since I'm new to this field I'm not sure if there's something else that a (edge?) router will do that the UTM cannot.

If it turns out my thought that it can replace the ASA is incorrect and it needs to be installed alongside it, is there typically any configuration that needs to be done to allow the UTM to sit in front of it (on the network)? Or does it not typically get placed there, instead being placed behind the ASA in the network. I ask because I've browsed through some of the config on the ASA and I'm seeing interfaces with different IPs assigned and other configurations so I want to make sure I am covering all required bases here before attempting the installation. 

The more I look into this the farther it seems to be from my knowledge, but I would really rather exhaust all of my options before looking into getting a contractor to help/do it.

TLDR: Can the Sophos UTM replace a Cisco ASA? If so is it whats done in most cases or just possible? If it doesn't replace the ASA are there configuration changes that need to take place on the ASA for it to work with the UTM?

Thank you for any help you can provide, sorry about the novice nature of these questions, this is sort of a trial by fire position for me.

Thanks,

Geoff



This thread was automatically locked due to age.
Parents
  • Geoff,

    Does your company have a paid license from Sophos or is just a trial? Also, I would highly discourage you from running a UTM on top Windows for a business installation. Performance and reliability will most likely suffer due to the overhead from Windows. You are better off installing UTM 9 directly on a piece of hardware or using it inside a bare bones hypervisor like ESXi.

    Doug

  • I imagine he's talking about Hyper-V so as long as it's a 'real' VM installation then it should work just the same as ESXi.

    That said I do agree - hardware wins.  We're running 2 UTMs as VMs with a lot of resources thrown at them and they never perform as well as the SG 210's that we're using for our clients.  So I do prefer the hardware versions if at all possible.

  • It is on Hyper-V yes, this was the guide I was given to follow and I set up the VM according to that, just waiting on the go ahead to install it. In regards to putting it straight onto some hardware, I dont believe thats an option for us at the moment but I will do some research and see if I can propose that instead, or an upgrade to that. Can UTM's "profile" be uploaded to a different device later? Or is it best to just set it up again. Also this is a paid license yes, not a trial.

    With the hardware portion, what terms should I research? I'm not used to this type of appliance, I thought it was all just switches, routers, and servers haha.

    Thanks Wayne for the info about your setup, that clears up what I thought I was seeing UTM being able to do. Although I still need to do more research on how to configure the ASA properly since it looks like we need to have the UTM in front of the ASA and before the WAN. So far my interactions with the router have been less than fruitful. Although im hoping it isnt too bad, just changing the interface on the router from our WAN(public ip) to the UTM ip. Once again though another project has taken precedence and I'll have to come back to this.

    Thanks all for the replies, I greatly appreciate it, makes me feel less stressed.

    -Geoff

  • Hi, Geoff, and welcome to the UTM Community!

    It's easy for a first-timer to make incorrect assumptions that result in design decisions that come back to haunt you later (e.g., The Zeroeth Rule in Rulz).  As this is not for your own use at home, I would urge you to find out if  your reseller has enough experience to do things right the first time, or if you need to contact Sophos for a recommendation in your area.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Geoff, and welcome to the UTM Community!

    It's easy for a first-timer to make incorrect assumptions that result in design decisions that come back to haunt you later (e.g., The Zeroeth Rule in Rulz).  As this is not for your own use at home, I would urge you to find out if  your reseller has enough experience to do things right the first time, or if you need to contact Sophos for a recommendation in your area.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data