Solved

Finding Blocked Ports in Sophos

Posted on 2015-01-20
2
506 Views
Last Modified: 2016-02-25
How does anyone make any use of the Sophos Logs? I only have 5 ports open so I should be seeing tons of blocked traffic like I did with Forefront. In sophos the firewall log is garbage and does not actually show anything getting blocked besides very ransom ports(57252). So how can I tell when a port is being blocked?

Also I setup SSL VPN and see absolutely no traffic on the firewall log and the VPN SSL log is crap as well and does not show anything being blocked. I have setup many firewalls and this one is the most difficult due to bad software.

And one last thing, the system will not update to 9.3, so again crap software.

Thanks
0
Comment
Question by:Biofilminc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 4

Expert Comment

by:Antyrael
ID: 40561634
I've been using Sophos UTM (previously Astaro) for a long time now and I always see lots of traffic being blocked in the live log.
Assuming logging works on your Sophos firewall, you have 2 options why you're seeing less than expected:
1) Certain traffic is blocked before it reaches your firewall, or
2) Your firewall rules allow for more than you have intended.

Sophos UTM creates some rules automatically, make sure you select to show all rules, so you have all the information.
If no automatic rules allow for unexpected traffic, try to temporarily disable your rules (but don't lock yourself out) and generate some incoming traffic to check if you see that being blocked (you could try some remote port scanning service if you don't have anything external to use, like https://pentest-tools.com/discovery-probing/tcp-port-scanner-online-nmap).
0
 
LVL 24

Accepted Solution

by:
Dirk Kotte earned 500 total points
ID: 40571165
good explanation of Antyrael.

i work many years this and other devices, ASTARO / SOPHOS configuration and logging is great.
But 9.210 has a logging-bug  :-)  fixed with 9.3xx

the update is offered after the vendor releases it. This take place successively with major releases.
If you wish to force the update, download the updatefile, import it manually and after installing this update.
With this major-update installed all following updates are recognized immediately.
0

Featured Post

Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question