This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAF Synology No Protection

Hi, I did manage to config WAF for Synology Sync drive. But i dont have any protection. While im uploading testing file "Eicar" it gets passthru...

Why i dont have AV, logs  and other options  turned on.

Thx.

#xg #synology #WAF #"web protection" #XG #SSL#nostandardport

Sophos XG v18 mr4



This thread was automatically locked due to age.
  • .

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • FormerMember
    0 FormerMember

    Hi Roman, Thanks for reaching out.

    You can use WAF to protect the access portal (web GUI) of your Synology device as long as it's behind XG and on top of that, you can also put an IPS policy in the WAF rule which can help you scan the rest of the traffic as well.

    I have tried this with a FreeNAS custom device I have in my LAN and works like a charm! :) 

  • I'm using WAF - it's working, I mean in some way. I did import certs cuz service is on https port. But scanning desont  block any malicious content like viruses etc. I'm using IPS it that policy, you can see it onpasted screenshots. The point is that ips doesn't block https traffic. I guess that if I have put cert for specific scenario then traffic should be decrypted by WAF rule ? So if I'm uploading some malicious files  - sophos  should drop it. ;)

    Thx for answer ;)

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • Anyone else?

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • I've wasted more than an entire year trying to get the basic WAF functionalities to work correctly; The AV has always a hit or miss, most of the times the traffic would never be sent to be scanned and most malware would just pass-through without any issues.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Oh. That wasnt a satisfying  answer to hear from ya :p  How someone like sophos could have such problems with basic thing. Theirs  solutions  are used in enterprise  environments... ;) WAF is so basic. Im using it for Home not a big deal but im wonder about companies.. it cant be so low level quality  thing ^^

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

  • Right now I don't have any other problem besides the AV and gzip compression.

    XSS / Application attacks / SQLi protections works just fine, It will only require a bit of tuning - of course that's expected from any other WAF.

    Edit: I've had a minor issue with SQLi protection before, but I gave up on researching It since not a lot of people are affected by It.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • So do I, only AV problems ;) btw, Im hosting Syno Drive on Synology and its working pretty great with WAF with no special tunning etc ;) But AV is failling all the tme. All test malware got pass. 

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb