• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 725
  • Last Modified:

Finding Blocked Ports in Sophos

How does anyone make any use of the Sophos Logs? I only have 5 ports open so I should be seeing tons of blocked traffic like I did with Forefront. In sophos the firewall log is garbage and does not actually show anything getting blocked besides very ransom ports(57252). So how can I tell when a port is being blocked?

Also I setup SSL VPN and see absolutely no traffic on the firewall log and the VPN SSL log is crap as well and does not show anything being blocked. I have setup many firewalls and this one is the most difficult due to bad software.

And one last thing, the system will not update to 9.3, so again crap software.

Thanks
0
Biofilminc
Asked:
Biofilminc
1 Solution
 
AntyraelICT SpecialistCommented:
I've been using Sophos UTM (previously Astaro) for a long time now and I always see lots of traffic being blocked in the live log.
Assuming logging works on your Sophos firewall, you have 2 options why you're seeing less than expected:
1) Certain traffic is blocked before it reaches your firewall, or
2) Your firewall rules allow for more than you have intended.

Sophos UTM creates some rules automatically, make sure you select to show all rules, so you have all the information.
If no automatic rules allow for unexpected traffic, try to temporarily disable your rules (but don't lock yourself out) and generate some incoming traffic to check if you see that being blocked (you could try some remote port scanning service if you don't have anything external to use, like https://pentest-tools.com/discovery-probing/tcp-port-scanner-online-nmap).
0
 
Dirk KotteSECommented:
good explanation of Antyrael.

i work many years this and other devices, ASTARO / SOPHOS configuration and logging is great.
But 9.210 has a logging-bug  :-)  fixed with 9.3xx

the update is offered after the vendor releases it. This take place successively with major releases.
If you wish to force the update, download the updatefile, import it manually and after installing this update.
With this major-update installed all following updates are recognized immediately.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now