This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Manual way for creating UTM in aws

Hi guys, 

 

Im trying to deploy Sophos UTM in AWS. 

However there are some restrictions with my client,

  1. we need to set permission boundary. 
  2. We cannot create VPC.
  3. We cannot create IAM user nor roles. 
  4. There is no internet access. So no IGW. 

I tried the cloudformation template provided by sophos UTM PAYG in my aws dev to no problem. 

When i try to manually recreate using AMI using this guide https://www.sophos.com/en-us/medialibrary/PDFs/documentation/UTM_on_AWS_AutoScalingGuide_v1.pdf, there are some issues, notably;

  1. The outbound gateway option is missing from the UTM webgui. The cloudformation has some magic paradigm f*kery going on, and its busting my nuts. 
  2. we tried manually creating the outbound gateway using https://community.sophos.com/kb/en-us/124431 it doesn't work well that i can't see it appearing in the UTM webgui. 
  3. We tried using the cloudformation template and entering existing vpc, but the stack fails. 

 

I tried asking support but they just gave me a turnaround and asked me to call the support line. 


So posting it up here for assistance as i'd like to setup the UTM for its NGFW, Firewall, WAF, and IPS and use it as a DMZ. 

Is there any cloudformation or manual guide or steps for manually deploying the sophos UTM into an existing vpc? and making it work without internet access?



This thread was automatically locked due to age.
  • Selamat pagi - welcome to the UTM Community!

    Your question is too broad for this venue.  You can easily get help for individual questions like, "Here's a picture of the Edit of xxxx.  What is incorrect?" 

    Sophos Support is a break-fix service, not a consulting/configuration service, so that's also not a place where you could get the help requested here.

    How to deploy Sophos UTM in Amazon Web Services VPCs with Cold Standby or Warm Standby High Availability (HA) is an older KB article, but it may help your situation better than 124431.

    Cheers - Bob 

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob. 

     

    Thanks for the pointer. 

    As i mentioned, everything works if you have full control to run the cloudformation and are able to create roles, and vpc. 


    When we run the cloudformation we are looking to run it using an existing vpc and using a fixed role instead of creating 1 for us. 

  • Moving this thread from General Discussion to the UTM on AWS forum.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA