<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Webserver protection setup problems</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/114536/webserver-protection-setup-problems</link><description>I&amp;#39;m attempting to set up Sophos UTM as Webserver protection, right now behind a different firewall, and running into issues. Looking at Sophos I may just use it as the main firewall in the future, but for now it has to be behind another as reverse proxy</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Webserver protection setup problems</title><link>https://community.sophos.com/thread/411784?ContentTypeID=1</link><pubDate>Mon, 12 Aug 2019 20:34:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:84305728-7885-4de8-aba1-720a10908e01</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Hi Scott and welcome to the UTM Community!&lt;/p&gt;
&lt;p&gt;Do you see anything in the WAF log that would indicate that it&amp;#39;s processing the incoming requests?&amp;nbsp; Please show pictures of the Edits of the Interface definition, the Virtual Server, Real Server and the Host object in the real server.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Webserver protection setup problems</title><link>https://community.sophos.com/thread/411646?ContentTypeID=1</link><pubDate>Sun, 11 Aug 2019 18:29:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:195dfb0c-bac0-49b2-8055-0edf304d93c2</guid><dc:creator>DouglasFoster</dc:creator><description>&lt;p&gt;1) I do not believe that you do not have bridge mode.&amp;nbsp; &amp;nbsp;Bridge mode looks like this:&lt;/p&gt;
&lt;p&gt;Switch --- UTM --- Firewall&lt;/p&gt;
&lt;p&gt;Two (or more) physical interfaces are bound together as one logical interface to UTM.&amp;nbsp; &amp;nbsp;Everything going to the firewall has to pass through UTM.&lt;/p&gt;
&lt;p&gt;From your description, you have this:&lt;/p&gt;
&lt;p&gt;Switch --- UTM&lt;br /&gt;&amp;nbsp; &amp;nbsp;\____________ Firewall&lt;/p&gt;
&lt;p&gt;In this mode, UTM only sees traffic that targets one of its addresses, so it can only do Standard Mode functions.&amp;nbsp; &amp;nbsp;For more detail on Standard and Transparent mode functions, see this post:&lt;/p&gt;
&lt;p&gt;&lt;a href="/products/unified-threat-management/f/general-discussion/100848/how-to-understand-utm-port-usage"&gt;https://community.sophos.com/products/unified-threat-management/f/general-discussion/100848/how-to-understand-utm-port-usage&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2) Basic process that I use for configuring a webserver:&lt;/p&gt;
&lt;p&gt;On UTM&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configure the real webserver and test it internally&lt;/li&gt;
&lt;li&gt;Get an SSL Certificate for the website so you can use HTTPS, which provides proof of server identity as well as encryption.&lt;/li&gt;
&lt;li&gt;Configure an Additional Network Address on UTM.&amp;nbsp; &amp;nbsp;(Using the primary address will create conflicts with the user portal.)&amp;nbsp; &amp;nbsp;Since UTM is behind your firewall, this will be an internal address.&lt;/li&gt;
&lt;li&gt;Create the virtual webserver and assign it to the chosen IP address and the (recommended) SSL certificate.&lt;/li&gt;
&lt;li&gt;Enable the webserver.&amp;nbsp; &amp;nbsp;If it can connect to the real webserver, the status indicator will go green.&amp;nbsp; &amp;nbsp;(May need to navigate away and come back to see the correct status light.)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On a test machine with an internal IP address&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a HOSTS file entry to force your test traffic to target the UTM virtual webserver address instead of the real webserver address.&lt;/li&gt;
&lt;li&gt;Enable a firewall profile with all protections enabled but in monitor mode.&lt;/li&gt;
&lt;li&gt;Do all of your tests&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Review the logs and disable tests that are throwing false positives.&lt;/li&gt;
&lt;li&gt;Decide whether to deploy to the internet in Monitor Mode or Reject Mode&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On the firewall&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a NAT rule from the chosen Internet address to the UTM virtual webserver address.&lt;/li&gt;
&lt;li&gt;Test again from an external PC.&lt;/li&gt;
&lt;li&gt;Enable Reject mode&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>