Our Sophos Management Server is installed behind a Palo Alto firewall, which is used to centrally update and manage all internal Sophos clients.
After new installation of this Sophos Management Server, we found update from Internet always failed. The Palo Alto firewall rule was configured to use FQDN addresses as destination. Based on Sophos support site,
“The Sophos Update Manager (SUM) server uses port 80 (http) and requires access to the following eight addresses:
- dci.sophosupd.com
- d1.sophosupd.com
- d2.sophosupd.com
- d3.sophosupd.com
- dci.sophosupd.net
- d1.sophosupd.net
- d2.sophosupd.net
- d3.sophosupd.net
“
Although all those eight ip addresses has been programed into Palo Alto firewall, unfortunately the firewall rule still does not work. Even we changed to any ip address in destination, there is still failed message.
Lets take a look Palo Alto firewall rule configured before:
and Palo Alto logs:
We found Palo Alto firewall treated some network connections as a threat and denied the file downloading from Sophos Update site.
Lets modify rule:
Now the Sophos Update Manager looks much better:
Youtube Video: A Quick Look of Sophos Enterprise Console 5.5:
Sophos更新配置
本文介绍了一种Sophos管理服务器在Palo Alto防火墙后的配置问题及解决方案。Sophos管理服务器安装后无法从互联网正常更新,经过排查发现是由于防火墙规则配置不当导致。通过调整规则并确保能访问特定的Sophos更新地址,最终解决了更新失败的问题。









365

被折叠的 条评论
为什么被折叠?



