4.1 Understanding Firewall Objects to Create Firewall Rules and Policies {Theory and Hands-on LAB }

Поділитися
Вставка
  • Опубліковано 19 вер 2024
  • In this Tutorial we will understand Firewall Objects such IP Host, IP Host Group, MAC host, FQDN (Fully Qualified Domain Name), FQDN Group, Country Object, Service Objects and Service Groups.
    Firewall Objects are helpful to create Firewall Rules and NAT policies. Customize Policies as per the requirement.
    Sophos XG Firewall Series: • Sophos XG Firewall || ...
    #SophosFirewallObject
    #CreateFirewallRulesandPolicies
    #IPHost
    #IPHostGroup
    #MACHost
    #FQDN
    #FullyQualifiedDomainName
    #CountryObjects
    #Services
    #ServiceGroups
    #FirewallRules
    #NATPolicies
    #MASQ
    #Interface
    #FirewallZones

КОМЕНТАРІ • 38

  • @gonzo6310
    @gonzo6310 Місяць тому

    Love you, thanks for your work

    • @NoorNetworks
      @NoorNetworks  Місяць тому

      My pleasure!

    • @NoorNetworks
      @NoorNetworks  11 днів тому

      If you are interested in VMware vSphere and AWS, please feel to write on noornetworks.training@gmail.com

  • @EpicWondererExpedition
    @EpicWondererExpedition Рік тому

    Thank you for sharing this playlist. God bless you.

  • @johnrepairingcenterjohnraj8858
    @johnrepairingcenterjohnraj8858 2 роки тому

    Salute sir explaination is good 💜

  • @colinhiggins4779
    @colinhiggins4779 11 місяців тому

    Just to be clear: two interfaces int he same zone does not mean intra-zone traffic flows between them without restrictions yes? We still need security policies / ACLs that define what traffic can pass between those interfaces?

    • @NoorNetworks
      @NoorNetworks  11 місяців тому

      Yes, by default two interfaces won't communicate to each other. You need to configure Rule to achieve this

  • @aksitsolutions1387
    @aksitsolutions1387 Рік тому

    Very Nice Explations

    • @NoorNetworks
      @NoorNetworks  Рік тому

      Thank you so much 🙂

    • @NoorNetworks
      @NoorNetworks  11 днів тому

      If you are interested in VMware vSphere and AWS, please feel to write on noornetworks.training@gmail.com

  • @amalbabu3660
    @amalbabu3660 Рік тому

    Nice presentation sir…i want to learn this

    • @NoorNetworks
      @NoorNetworks  Рік тому

      Keep watching. If you have any doubts feel free to ask :)

    • @NoorNetworks
      @NoorNetworks  11 днів тому

      If you are interested in VMware vSphere and AWS, please feel to write on noornetworks.training@gmail.com

  • @naiksawan
    @naiksawan 11 місяців тому

    Thank you very much for such wonderful video. learning through your guidance. Have got stuck in one step. as i am not able to ping or access internet on virtual machine client pc-1 but i can ping firewall ip. my internet connected to Mobile data. do here i need to change something. Please help.

    • @NoorNetworks
      @NoorNetworks  11 місяців тому +1

      Check if you are able to ping 8.8.8.8 from your Sophos XG Firewall and let me know

    • @naiksawan
      @naiksawan 11 місяців тому

      @@NoorNetworks Bro, thank you so much.. have figure it out as there was an auto bridging issue so manually added WiFi interface and its worked. 🙏.. keep loading more. GBU

    • @naiksawan
      @naiksawan 10 місяців тому

      @NoorNetworks Bro, can you please guide on how to access Internal firewall to outside network.
      think we can use directly without vpn through Https please correct if wrong.

    • @NoorNetworks
      @NoorNetworks  10 місяців тому +1

      It is not advisable to do so and it is not a good practice. Doing so will add a high security risk.
      However, if you just want to see for learning purpose, you can do it by opening https access of your firewall over a wan port. In coming tutorials I have shown you how to manage these settings for LAN Ports (Similarly, you can do it for WAN Port)

  • @olusoladamilare7639
    @olusoladamilare7639 2 роки тому

    Nice explanation..pls without all this configuration does it mean it will not move traffic from lan to wan.. because I have been following all your previous tutorial and am using it for my sophos deployment for a client..

    • @NoorNetworks
      @NoorNetworks  2 роки тому

      By default traffic from any zone to any zone is drop in firewall. If you want to allow traffic from specific zone to specific zone, you must create a firewall rule as per the requirement.

    • @olusoladamilare7639
      @olusoladamilare7639 2 роки тому

      What if the client does not have on premises AD I have done the configuration up to DHCP ND DNS level..I am to test live tomorrow on the client environment..
      But I have not on onboard the AD on the sophos firewall.. will it push traffic once a cable is connected to the wan interface?

    • @NoorNetworks
      @NoorNetworks  2 роки тому

      Your AD must be reachable from your Sophos Firewall for integration... that's it!!!

  • @guthababu8656
    @guthababu8656 Рік тому

    Hi Mr. Noor, I am unable ping 1from the sophos firewall dashboard using diagnostic and FQDN host , I had followed your video and having this issue( Video 4.1)

    • @NoorNetworks
      @NoorNetworks  Рік тому

      Please re-check your network configuration in vmware workstation

  • @ayollootika4006
    @ayollootika4006 Рік тому

    I can ping Port A IP Address from PC1 and PC2 just find. But I am not able to ping Google DNS. What am I missing?

    • @NoorNetworks
      @NoorNetworks  Рік тому

      check you WAN Interface Configuration and I believe you have configured your DNS settings properly. Additionally, check your VM Network Adapter settings.

  • @cosmxd
    @cosmxd Рік тому

    Very nice videos! how can i set it up on my physical PC? i would like to make a home-lab that doesn't require a virtual management station. Your prompt response will be appreciated

    • @NoorNetworks
      @NoorNetworks  Рік тому

      From your comment I understand that you want to deploy firewall on you hardware and not as a virtual machine, is it right?

    • @cosmxd
      @cosmxd Рік тому

      @@NoorNetworks yes thats correct, id like to deploy xg firewall on my hardware

    • @NoorNetworks
      @NoorNetworks  Рік тому +1

      Follow this steps as the question you are asking is different from the topic.
      docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/VirtualAndSoftwareAppliancesHelp/SoftwareAppliance/SoftAppWindowsInstall/index.html

    • @cosmxd
      @cosmxd Рік тому

      ​@@NoorNetworks great, thank you for your assitance

  • @timadfz4757
    @timadfz4757 Рік тому

    When I move from another place to another Internet network, and when I open a window that is associated with VMware, the Internet does not appear. Why?

    • @NoorNetworks
      @NoorNetworks  Рік тому +1

      Because IP Scheme may change to another place. You have bridge your WAN Interface and assign static IP to your Sophos Firewall which belongs to the network where you did this configuration
      If you have any further questions please feel free to ask

    • @timadfz4757
      @timadfz4757 Рік тому

      @@NoorNetworks So I can't change the ip address in port B static in sophos depending on where in the network. Should I install a firewall again if I change location?

    • @NoorNetworks
      @NoorNetworks  Рік тому +1

      Yes you can change the IP Address of WAN interface as per IP Scheme and changes in the Rules and Policies as required.
      No, need to install firewall again

    • @timadfz4757
      @timadfz4757 Рік тому

      @@NoorNetworks ok thank you so much
      Ur the best 🌹🌹🌹

    • @NoorNetworks
      @NoorNetworks  Рік тому +1

      Glad to hear that your issue is resolved :)