How To Create vLANs, Firewall Rules, Port Forwards, Dynamic DNS, Traffic Inspection And More!

แชร์
ฝัง

ความคิดเห็น • 34

  • @Glatze603
    @Glatze603 10 หลายเดือนก่อน +4

    Hi Jim, Sophos XG is awesome. I find special functions compared to other systems (e.g. the opnsense) are the application filters, the web policies and the real-time log viewer. Unfortunately, Sophos has still not managed to integrate a full-fledged DNS server. This is where opnsense scores. Thank you for this detailed video.

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน +1

      Agreed. I guess it's the difference between a full enterprise solution and something more for the mid tier. Typically DNS is done outside of the firewall

  • @Skylake-dp4xu
    @Skylake-dp4xu 5 หลายเดือนก่อน

    Thank you for sharing this! I have a fresh install of Sophos XG and tried to expose a port using server access assistant DNAT. Firewall logs shows the port is accepted but I'm not getting a inbound connection and just outbound only. Online port checker says the port is closed :(. I just wanted to know if there's a setting I need to check prior to port forwarding? Thanks.

  • @zippi777
    @zippi777 10 หลายเดือนก่อน +1

    Hi Jim, I had downloaded Sophos XG for some time and had not yet installed it as a vm.
    Time has come!
    As usual....thank you!

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      Awesome, I hope you like it.

  • @mrd4233
    @mrd4233 10 หลายเดือนก่อน +1

    Really good tutorial! I learn something new "Promiscuous mode" that I wasn't aware! Thanks Jim :)

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน +2

      Thanks 👍 it's an important one that is often missed and people wonder why the vLAN doesn't work.

  • @petervogt8309
    @petervogt8309 10 หลายเดือนก่อน +1

    Perfect timing, just watched your previous FW vids and got the bits to build one. Thanks Jim!

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      Awesome 😎

  • @antoniomax3163
    @antoniomax3163 10 หลายเดือนก่อน +1

    Sophos only hardware? Maybe for home user - virtual mashine?

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      I use a virtual Sophos XG in high availability, but the core concepts are applicable elsewhere.

  • @dimasshidqiparikesit1338
    @dimasshidqiparikesit1338 10 หลายเดือนก่อน +1

    Is it possible to use dynamic dns behind CGNAT?

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      Yes, it should be but I'm not sure what good it would do. Check out my headscale video

  • @ws_stelzi79
    @ws_stelzi79 10 หลายเดือนก่อน +1

    I see a port configured for Factorio. One question: does it help to make even more Green, Red or Blue Circuits? 🤪

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      Well spotted! It's Sophos, obviously blue ;)

    • @pyr0ish
      @pyr0ish 4 หลายเดือนก่อน +1

      @@Jims-Garage A man of culture I see

  • @Popcorncandy09
    @Popcorncandy09 9 หลายเดือนก่อน +1

    Question, Do you have to create an allow firewall rule for other VLANs to access those DNS server IPs? or could you get round this easily and more streamlined by pointing the VLANs to the firewall and the firewall would be able to pass it on? I've never been sure if the client devices needed direct access to the Pi-Hole or not.

    • @Jims-Garage
      @Jims-Garage  9 หลายเดือนก่อน +1

      Yes, clients need access to the DNS server, so a firewall rule

    • @Popcorncandy09
      @Popcorncandy09 9 หลายเดือนก่อน +1

      @@Jims-Garage so i would need a rule allowing all VLANs access to the DNS server on port 53? rather than they able to access it via jus being pointed to their firewall IP address?

    • @Jims-Garage
      @Jims-Garage  9 หลายเดือนก่อน +1

      @@Popcorncandy09 yes, it's not a DNS proxy

    • @Popcorncandy09
      @Popcorncandy09 9 หลายเดือนก่อน

      Speaking of proxies, i have tried to follow your port forwarding part of the video to point to my reverse proxy running in docker on my synology nas, if i use the scheduling wizard it does not seem to work...i use port 4443 instead of 443 so i need to go from 443 incoming to 4443 on the reverse proxy IP. but when i create custom services with this and setup the port forward it doesnt seem to work correctly. Am i missing something ? @@Jims-Garage

  • @themarksmith
    @themarksmith 10 หลายเดือนก่อน +1

    How does Sophos XG home compare to pfsense/OPNsense and can it be run in a VM with 2 physical NICs?

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน +1

      Quite similar, except XG is not open source, but is more common in Enterprise. I run two virtual machine XGs, both with 3 NICs. They run in high availability mode for failover (I have a video on that)

    • @themarksmith
      @themarksmith 10 หลายเดือนก่อน

      @@Jims-Garage Thanks for the reply! I was just about to set up an OPNsense VM to protect my LAN and 5 WAN ips but after seeing your vid I am now considering the free, but limited to 4 cores and 6gb XG home edition (I'm a cheap skate!) - so your video was useful! Love your channel - thanks!

    • @DigiDoc101
      @DigiDoc101 10 หลายเดือนก่อน +1

      Nice overview video. Have you noticed slow routing speeds at 10gb using the free Home license?

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      @@DigiDoc101 no, I max it out. 4 cores and 6GB ram is more than enough for 10Gb.

  • @JasonsLabVideos
    @JasonsLabVideos 10 หลายเดือนก่อน +1

    God video on this Sophos stuff !

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      Thanks, I'm also doing some OpnSense ones now so people have a choice.

  • @Vaillant44
    @Vaillant44 10 หลายเดือนก่อน +1

    Hey James, thanks for the video.

    • @Jims-Garage
      @Jims-Garage  10 หลายเดือนก่อน

      You're welcome :)

  • @khanhthedag7269
    @khanhthedag7269 8 หลายเดือนก่อน +1

    Hi Jims, very nice and it is educational. thanks.

    • @Jims-Garage
      @Jims-Garage  8 หลายเดือนก่อน

      Very welcome, glad it helped.

    • @khanhthedag7269
      @khanhthedag7269 8 หลายเดือนก่อน

      You have 2 Proxmox Asus and Dell. (Cluster). they are on same network? If also want make 2 Proxmox. I must give the in the same IP Range (e.g. 192.168.100.2 (for 1) and 192.168.100.3 (for 2.), right?.
      or can I also make the proxmox on VLAN (ID 5)? @@Jims-Garage