This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SOPHOS UTM Full transparent Mode, what features will work through....

Hi,

 

I have an customer where he don’t want to disturb his existing network for POC and if things goes well then continue with SOPHOS in Full Transparent mode.

 

EXISTING NETWORK:

                                    INTERNET Router 1                      Internet ROUTER 2 

                                                                           SWITCH (Both internet Links are connected to Switch)

                                      Juniper Firewall (Active) <<Link>>  Juniper Firewall (Passive)

                                                        Core Switch 1 <<Link>>   Core Switch 2

                                                               LAN Network with Multiple VLANS

From the above we need SOPHOS in Full transparent mode in two position with almost all features except VPN, Endpoint and Wireless.

 

Scenario 1 : Sophos Between  Switch (Internet Router connected with) and Juniper.

 

Scenario 2: Sophos Between Juniper and Core Switch.

 

Must meet features:

  • AD SSO for web proxy (Full transparent Mode),  Web Reports should include username as of AD SSO
  • AV Scanning for Web and Email traffic Including attachment.
  • IPS , ATP etc.

 

 

I hope above explanation is clear if not please feel free query, sorry say but this is very important POC and it has very short time limitation to prove SOPHOS can fit their requirement.

 

Note: if you have any other scenario’ s which can meet above requirement please share it with us.

 

Thanks in advance..



This thread was automatically locked due to age.
  • I would think that the second Scenario would come closest to what you want with Web Filtering.

    Will the Junipers no longer be doing IPS if this is successful?

    I don't recommend using the SMTP Proxy in Transparent mode. I think you will have less effort for the POC if you just do a standard configuration like in community.sophos.com/.../178769. Or, are you talking about using the POP3 Proxy?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA