This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bulk management of XG hosts, services, firewall rules

For those who are not a Sophos partner - For multiple xg's managed through Central rather than on-premises SFM is API currently the only option to perform bulk deployment of objects such as hosts, fqdn, services, firewall rules to multiple xg's that don't have uniform configurations?  Is this functionality ever coming to the non-partner Central portal?



This thread was automatically locked due to age.
Parents Reply Children
  • I've avoided the group functionality in Central due to the "Assigning a firewall to the group will apply a default configuration to the firewall. It may change the current firewall configurations" warning.  XG's here were already deployed with custom configurations at remote locations prior to the option of Firewall Management in Central so the concern is that grouping now could break them.  Your xml writeup is appreciated.

  • Thats not completely true. Let me explain, how CM works. CM uses a XML approach with Key value "Name". So to speak, it will check, if your "Name" Object is the same, if not, it will update it with the value of CM. For example ATP: You have Disable ATP (tick box) in CM, it is enabled on XG Webadmin. Using CM, it will remove the tick box and disable the setting. Firewalls for example will not be removed. Only added, if you have new Rules created in CM. 

    A new created group is "empty". So there are no firewall rules or Objects. The only Objects are the factory default objects (for example Host objects, created by the wizard, which every XG has). 

    Tick box features will be overwritten. See example ATP above. 

    __________________________________________________________________________________________________________________