?
Solved

Finding Blocked Ports in Sophos

Posted on 2015-01-20
2
Medium Priority
?
531 Views
Last Modified: 2016-02-25
How does anyone make any use of the Sophos Logs? I only have 5 ports open so I should be seeing tons of blocked traffic like I did with Forefront. In sophos the firewall log is garbage and does not actually show anything getting blocked besides very ransom ports(57252). So how can I tell when a port is being blocked?

Also I setup SSL VPN and see absolutely no traffic on the firewall log and the VPN SSL log is crap as well and does not show anything being blocked. I have setup many firewalls and this one is the most difficult due to bad software.

And one last thing, the system will not update to 9.3, so again crap software.

Thanks
0
Comment
Question by:Biofilminc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 4

Expert Comment

by:Antyrael
ID: 40561634
I've been using Sophos UTM (previously Astaro) for a long time now and I always see lots of traffic being blocked in the live log.
Assuming logging works on your Sophos firewall, you have 2 options why you're seeing less than expected:
1) Certain traffic is blocked before it reaches your firewall, or
2) Your firewall rules allow for more than you have intended.

Sophos UTM creates some rules automatically, make sure you select to show all rules, so you have all the information.
If no automatic rules allow for unexpected traffic, try to temporarily disable your rules (but don't lock yourself out) and generate some incoming traffic to check if you see that being blocked (you could try some remote port scanning service if you don't have anything external to use, like https://pentest-tools.com/discovery-probing/tcp-port-scanner-online-nmap).
0
 
LVL 24

Accepted Solution

by:
Dirk Kotte earned 2000 total points
ID: 40571165
good explanation of Antyrael.

i work many years this and other devices, ASTARO / SOPHOS configuration and logging is great.
But 9.210 has a logging-bug  :-)  fixed with 9.3xx

the update is offered after the vendor releases it. This take place successively with major releases.
If you wish to force the update, download the updatefile, import it manually and after installing this update.
With this major-update installed all following updates are recognized immediately.
0

Featured Post

WordPress Tutorial 1: Installation & Setup

WordPress is a very popular option for running your web site and can be used to get your content online quickly for the world to see. This guide will walk you through installing the WordPress server software and the initial setup process.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question