Advisory: Sophos Endpoint - "Your connection isn't private" We're aware of a certificate issue and are actively working to resolve. Please see: KB-000045954 for the latest updates.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Manual way for creating UTM in aws

Hi guys, 

 

Im trying to deploy Sophos UTM in AWS. 

However there are some restrictions with my client,

  1. we need to set permission boundary. 
  2. We cannot create VPC.
  3. We cannot create IAM user nor roles. 
  4. There is no internet access. So no IGW. 

I tried the cloudformation template provided by sophos UTM PAYG in my aws dev to no problem. 

When i try to manually recreate using AMI using this guide https://www.sophos.com/en-us/medialibrary/PDFs/documentation/UTM_on_AWS_AutoScalingGuide_v1.pdf, there are some issues, notably;

  1. The outbound gateway option is missing from the UTM webgui. The cloudformation has some magic paradigm f*kery going on, and its busting my nuts. 
  2. we tried manually creating the outbound gateway using https://community.sophos.com/kb/en-us/124431 it doesn't work well that i can't see it appearing in the UTM webgui. 
  3. We tried using the cloudformation template and entering existing vpc, but the stack fails. 

 

I tried asking support but they just gave me a turnaround and asked me to call the support line. 


So posting it up here for assistance as i'd like to setup the UTM for its NGFW, Firewall, WAF, and IPS and use it as a DMZ. 

Is there any cloudformation or manual guide or steps for manually deploying the sophos UTM into an existing vpc? and making it work without internet access?



This thread was automatically locked due to age.
Parents Reply
  • Hi Bob. 

     

    Thanks for the pointer. 

    As i mentioned, everything works if you have full control to run the cloudformation and are able to create roles, and vpc. 


    When we run the cloudformation we are looking to run it using an existing vpc and using a fixed role instead of creating 1 for us. 

Children
No Data