This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multipath rules: Block specific traffic for an interface

Hello to all!

I have an ADSL connection and I also have a 3G modem connected to my UTM

I wanted to use the 3G modem as a failover, but due to the fact that the 3G subscription is a prepaid one with a limit of 1GB/month I want to allow only HTTP/HTTPS and SMTP connections when the 3G is used (I mean no torrenting, no media streaming allowed)

I found some help from the following thread : https://community.sophos.com/products/unified-threat-management/f/55/p/79077/302143#302143

After unplugging the phone cable, though, I noticed that by using Web Surfing as the service, youtube was still working

So I modified the rule by unchecking the skip rule on interface error option :

With this change I have no internet at all, though..

To my understanding, by unchecking this and the interface is down, it won't allow any traffic, so no internet is the normal behavior. But since the previous rule dictates web surfing allowed, shouldn't I have available internet???

So, to sum up, if "skip rule on interface error" is checked I have youtube working which I don't want.

If I have the setting unchecked I have no internet at all

What I want is to be able to browse the internet when the 3G interface takes over, but no torrenting and no media streaming aloowed to save prepaid mobile data

Any ideas please?



This thread was automatically locked due to age.
  • Hello again, and thanks for the suggestion..

    However there are a lot of feature requests with much higher interest for many which are not fulfilled yet. So I doubt this will ever make it to a sophos release.

    I am using a home licence and have sophos installed on a PC.

    If the XG has that feature this is interesting. However, TBH, I already gave it a try in a virtual machine and I don't like it. I found it all over the place. [:S]

    I read there are also stuff included in the UTM that are not yet available on XG.

    So I am sticking with the UTM until XG matures enough, or at least when a migration tool is created...

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)