Solved

Finding Blocked Ports in Sophos

Posted on 2015-01-20
2
403 Views
Last Modified: 2016-02-25
How does anyone make any use of the Sophos Logs? I only have 5 ports open so I should be seeing tons of blocked traffic like I did with Forefront. In sophos the firewall log is garbage and does not actually show anything getting blocked besides very ransom ports(57252). So how can I tell when a port is being blocked?

Also I setup SSL VPN and see absolutely no traffic on the firewall log and the VPN SSL log is crap as well and does not show anything being blocked. I have setup many firewalls and this one is the most difficult due to bad software.

And one last thing, the system will not update to 9.3, so again crap software.

Thanks
0
Comment
Question by:Biofilminc
2 Comments
 
LVL 4

Expert Comment

by:Antyrael
ID: 40561634
I've been using Sophos UTM (previously Astaro) for a long time now and I always see lots of traffic being blocked in the live log.
Assuming logging works on your Sophos firewall, you have 2 options why you're seeing less than expected:
1) Certain traffic is blocked before it reaches your firewall, or
2) Your firewall rules allow for more than you have intended.

Sophos UTM creates some rules automatically, make sure you select to show all rules, so you have all the information.
If no automatic rules allow for unexpected traffic, try to temporarily disable your rules (but don't lock yourself out) and generate some incoming traffic to check if you see that being blocked (you could try some remote port scanning service if you don't have anything external to use, like https://pentest-tools.com/discovery-probing/tcp-port-scanner-online-nmap).
0
 
LVL 23

Accepted Solution

by:
Dirk Kotte earned 500 total points
ID: 40571165
good explanation of Antyrael.

i work many years this and other devices, ASTARO / SOPHOS configuration and logging is great.
But 9.210 has a logging-bug  :-)  fixed with 9.3xx

the update is offered after the vendor releases it. This take place successively with major releases.
If you wish to force the update, download the updatefile, import it manually and after installing this update.
With this major-update installed all following updates are recognized immediately.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now