This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SG220 UTM9 Country blocking not blocking port 4444

Hello,

I'm a newbie in the Sophos community and apologize if my question has already been answered somewhere.

I've activated the Country blocking on our SG210 UTM9 v 9-705.3 appliance and was quite happy to check that the box no more accepted incoming requests (https redirection essentially) coming from countries where we don't have users.
From a PC i created a VPN tunnel to a blocked country, tried an access to one application behind the firewall and got no response, as awaited.
I also used Nmap to check,but discovered that with an "Nmap -Pn" port 4444 was found and, indeed, an https allowed me to login on the firewall.
I hoped the Country blocking would close all ports and make the firewall totally unseen from these countries.
Wrong understanding or bad configuration ?

Thanks in advance for your help.

Yan



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi Yan, Thanks for reaching out to Sophos Community.

    You can allow specific networks to access UTM's WebAdmin by creating network/host definitions and allowing them in "Management > WebAdmin Settings > Allowed Networks"

  • Hi Devesh,

    Thanks for your fast answer  and tip. I'll try that... but just realize that country blocking applies to ALL traffic (in and outnound). So it has a huge impact and i'll have to be very carefull.
    Anyway, thanks for your help, i see now where to limit port 4444 access.

    Have a nice day, Devesh,

    Regards,

    Yan

  • FormerMember
    0 FormerMember in reply to Yan Benoist

    You're welcome Yan.

    You can also add exceptions (Network Protection > Firewall > Country blocking exceptions) if you have blocked any countries for specific services as well.