This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connect client to Symantec Protection Center via Sophos

Dear all

I have a diagram below:

I have 3 VLAN :

VLAN 1 has IP: 192.168.1.0/24. This VLAN is possible to access full Internet (Open full services on Sophos firewall)

VLAN 1 has IP: 192.168.2.0/24: This VLAN   only uses LAN only ( Block HTTP and https

VLAN 3 has IP: 192.168.0.0/24: This is VLAN for Server

On Sophos firewall. I only create 2 policies for VLAN 1 and VLAN 2 as above.

My VLAN 1 is possible to update Symantec package from Symantec Protection Center but VLAN 2 is impossible to update.
If I open full internet for VLAN 2 then possible to update.
I tried to create a new policy on Sophos and accept VLAN 2 to Symantec Server via HTTP and HTTPS but still impossible to update.
Could you help me to resolve or guide me on what should I do?

Thanks



This thread was automatically locked due to age.
Parents Reply Children
  • FormerMember
    0 FormerMember in reply to Minh Pham Cong

    Hi Minh,

    In the same firewall rule, add all the services along with HTTP and HTTPS. This is to allow traffic for all the services if the Symantec server uses any custom port to fetch/deliver updates.

  • Hi Devesh

    Thank you for your support.

    If the same firewall rule and add HTTP and HTTPS, my VLAN 2 will have full Internet. I only want VLAN 2 to use LAN.
    Please kindly help me with this.

    Thanks

  • Hi Devesh
    I just got message below when I tried to update Symantect client to Symantec Center via Sophos
    "ssl public key does not match pinned public key"
    Could you pls help me this case?

    Thanks

  • FormerMember
    0 FormerMember in reply to Minh Pham Cong

    Hi Minh, This seems more like an issue from your client or Symantec server end. Looking at your network diagram, It seems that Sophos is just acting as a gateway allowing traffic to pass amongst two separate networks. With that given, XG doesn't seem to cause the error. 
    But rather than leaving it dry, I would ask to check and confirm a few things to substantiate further. Let me know whether the created rule is set to filter any web/application traffic and does it have HTTPS decryption turned on? 

  • Hi Devesh
    Thank you for your reply.
    I think the root cause from Sophos from my rule. If I allow any services. Symantec works normally.

    LAN: 192.168.2.0/24

    WAN: 192.168.0.0/24

    My rule Accept

    Lan to WAN : 
    Source: LAN - any
    Destination: WAN  - any - Allow all services except for HTTP and HTTPS.
    NO HTTPS, HTTP descryption.

    No filter web, no filter application.

  • FormerMember
    +1 FormerMember in reply to Minh Pham Cong

    It seems that some communication is taking place on port 443 from the client to your Symantec server.

    To verify this further, You can run this command on CLI "drop-packet-capture 'host <SourceIP> and port 443" (Option 4 > Console) and run the update. This will give you the reason and the packets which were dropped.

    For this, You can either clone the existing rule or create a new one, Keep the VLAN 2.0/24 in source, Symantec server's IP in destination, and allow HTTP & HTTPS. This way, you're only granting Port 80 and 443 access to Symantec server from VLAN2.

    Hope this helps

  • I tried to input the command below Aerial tramway

    drop-packet-capture host 192.168.0.1 and port 443 but it informed %Error: Unknown Parameter 192.168.0.1.
    And I also clone the rule as your requirement even though I added any services but still impossible to update.
    I don't know where is root cause. Kindly help me one more time.

    Thanks

  • FormerMember
    0 FormerMember in reply to Minh Pham Cong

    You forgot to add ' before the host 

  • Hi Devesh
    I run the command successfully. Pls kindly see an image and give me your comment.
    I just met a problem, from VLAN 2, I can't scan from Photocopier ro client even I added SMB protocol to service but still error.
    OMG,Pls kindly help me. Now only you help me this case.

    Tks

  • FormerMember
    0 FormerMember in reply to Minh Pham Cong

    I have replied to your DM to collect captures and logs further