How to perform the actual migration from UTM to SFOS

I'm a long-time UTM home user but don't claim to be an expert. So how does one migrate from UTM to SFOS?

It would be very beneficial if the Sophos Engineers would provide a tutorial on everything from adding another Sophos appliance to a step-by-step comparison on how things are done differently, section by section when comparing the two. For instance, "This is how you set up WAF rules and policies in the UTM. This is how you accomplish the same thing in SFOS", using real examples. I truly believe a video tutorial series, which shows an actual migration, would help Sophos keep its customer base.

Maybe I'm wrong, but I don't think it is possible to create and maintain a set of 'UTM to SFOS' migration scripts which are100% reliable and work for all use-case scenarios. I think the best approach would be to add a SFOS box or VM to an existing UTM environment so that you can manually re-create your current setup on the new SFOS appliance--gradually, portion-by-portion, so that you can thoroughly test each piece that's been moved to the new SFOS appliance while maintaining the rest on the UTM.

So let's start with step one. How do you add a new SFOS box or VM to an existing UTM network so that you can access both. Which interfaces do you connect and are there any routes that need to be created?



Spelling
[edited by: Jeff x at 3:36 PM (GMT -8) on 7 Jan 2024]
Parents
  • its is hard to do a conversion when the product goes from intuitive to unintuitive. We tried hard on many firewalls, but SFOS is a broken product made for smb. We finally went to another vendor after to many failed tries

    As a product that that in most cases where better in design than a lot of product out there, we can hope that someone at Sophos would do the world and community a favor and opensource as much of the UTM/Astaro as possible.

    Thank you Sophos for the 10+ years.

  • rMI said:

    ...when the product goes from intuitive to unintuitive.

    I certainly agree on this point. However, I need IPS for ingress traffic and pfsense only does non-encrypted traffic which is useless. I'm not sure about Opnsense with the paid Zenarmor subscrption but I also don't want any cloud management. This is the main reason why I want to try and learn SFOS. Unless I'm wrong, you can terminate SSL traffic with the Sophos WAF and use IPS on the unencrypted traffic so that you do not have to do the MITM thing. This is how I was doing IPS with the UTM and it worked great. Caught a lot of bad traffic; just have to tweak the rules to minimize false-positives.

    What SFOS issues were you not able to fix, which caused you to go to another vendor? Unfortunately, I just don't see anything else out there for home lab user that want IPS.

    --------------------------------------------------------------------
    Sophos UTM 9.719-3 - Home User
    Virtual machine on Dell Optiplex 3070
    i3-9100 @ 3.60 GHz, 16 GB RAM
    --------------------------------------------------------------------

Reply
  • rMI said:

    ...when the product goes from intuitive to unintuitive.

    I certainly agree on this point. However, I need IPS for ingress traffic and pfsense only does non-encrypted traffic which is useless. I'm not sure about Opnsense with the paid Zenarmor subscrption but I also don't want any cloud management. This is the main reason why I want to try and learn SFOS. Unless I'm wrong, you can terminate SSL traffic with the Sophos WAF and use IPS on the unencrypted traffic so that you do not have to do the MITM thing. This is how I was doing IPS with the UTM and it worked great. Caught a lot of bad traffic; just have to tweak the rules to minimize false-positives.

    What SFOS issues were you not able to fix, which caused you to go to another vendor? Unfortunately, I just don't see anything else out there for home lab user that want IPS.

    --------------------------------------------------------------------
    Sophos UTM 9.719-3 - Home User
    Virtual machine on Dell Optiplex 3070
    i3-9100 @ 3.60 GHz, 16 GB RAM
    --------------------------------------------------------------------

Children
No Data