Sophos XG Firewall Web Interface Reference and Admin Guide v16.5

Add to My manuals
627 Pages

advertisement

Sophos XG Firewall Web Interface Reference and Admin Guide v16.5 | Manualzz

| Monitor and Analyze | 31

Support Access

- Use this page to grant support staff temporary access to your device.

Tools

Using the Tools page, one can view the statistics to diagnose the connectivity problem, network problem and test network communication. It assists in troubleshooting issues such as hangs, packet loss, connectivity, discrepancies in the network. The page covers:

Ping

Traceroute

Name Lookup

Route Lookup

Consolidated Troubleshooting Report

Ping

Ping is the most common network administration utility used to test the reachability of a host on an Internet Protocol

(IP) network and to measure the round-trip time for messages sent from the originating host to a destination computer.

Ping sends ICMP echo request/replies to test the connectivity to other hosts. Use standard ICMP ping to confirm that the server is responding. Ping confirms that the server can respond to an ICMP ping request.

Use Ping diagnostically to:

• Ensure that a host computer you are trying to reach is actually operating or the address is reachable or not

• Check how long it takes to get a response

• Get the IP address from the domain name

• Check for the packet loss

The parameters used are:

IP Address/Host Name

Specify the IP address (IPv4/IPv6) or fully qualified domain name to be pinged.

Ping determines the network connection between the device and a host on the network. The output shows if the response was received, packets transmitted and received, packet loss if any and the round-trip time. If a host is not responding, ping displays 100% packet loss.

IP Family

Select the type of IP family from the options available:

Available OptionsIPv4IPv6

Interface

Select the interface through which the ICMP echo requests are to be sent.

Size

Specify the ping packet size, in bytes.

Default: 32 bytes

Size Range: 1 to 65507

| Monitor and Analyze | 32

Figure 7: Ping

Traceroute

Traceroute is a useful tool to determine if a packet or communication stream is being stopped at the device, or is lost on the Internet by tracing the path taken by a packet from the source system to the destination system, over the

Internet.

Use Traceroute to:

• find any discrepancies in the network or the ISP network within milliseconds.

• trace the path taken by a packet from the source system to the destination system, over the Internet.

The parameters used are:

IP Address/Host Name

Specify the IP address (IPv4/IPv6) or fully qualified domain name.

Traceroute determines the network connection between the device and a host on the network. The output shows all the routers through which data packets pass on way from the source system to the destination system, maximum hops and total time taken by the packet to return measured in milliseconds.

IP Family

Select the type of IP family from the options available:

Available OptionsIPv4IPv6

Interface

Select the interface through which the requests are to be sent.

Figure 8: Traceroute

Name Lookup

Name Lookup is used to query the domain name service for information about domain names and IP addresses. It sends a domain name query packet to a configured domain name system (DNS) server. If a domain name is entered,

| Monitor and Analyze | 33 the return is an IP address to which it corresponds, and if an IP address is entered, then the domain name is returned to which it corresponds. In other words, Name Lookup reaches out over the Internet to do a DNS lookup from an authorized name server, and displays the information in user understandable format.

The parameters used and their descriptions are:

IP Address/Host Name

IP address (IPv4/IPv6) or fully qualified domain name that needs to be resolved.

DNS Server IP

Select the DNS server to which the query is to be sent.

Select Lookup using all Configured Servers to view all the available DNS servers configured in the device. Selecting this option will also provide information about the time taken by each DNS sever to resolve the query. Based on the response time,of each server, you can prioritize the DNS server.

Figure 9: Name Lookup

Route Lookup

If you have routable networks and wish to search through which interface the device routes the traffic then lookup the route for the IP address (IPv4/IPv6).

Figure 10: Route Lookup

Consolidated Troubleshooting Report

To help the Support team to debug the system problems, a troubleshooting report can be generated which consists of the system’s current status file and log files. The file contains details like a list of all the processes currently running on the system, resource usage etc. in encrypted form.

The administrator has to generate and mail the saved file to Support for diagnosing and troubleshooting the issue.

The file will be generated with the name: CTR_<APPKEY>__<MM_DD_YY>_<HH_MM_SS> where

• APPKEY is the device key of the device for which the report is generated

• MM_DD_YY is the date (month date year) on which the report is generated

• HH_MM_SS is the time (hour minute second) at which the report is generated

By default, the debug mode is off for all the subsystems. Before generating a log file, enable the debug mode by executing following command at the command line: console> diagnostics subsystems <subsystem name> debug on

Note: Debug mode cannot be enabled, if you only want to generate a system snapshot.

advertisement

Key Features

  • Firewall rules
  • Web filtering
  • Intrusion prevention
  • VPN
  • Wireless management
  • Email security
  • Advanced threat protection

Related manuals

Frequently Answers and Questions

What is the purpose of Sophos XG Firewall?
Sophos XG Firewall is a network security appliance designed to protect your network from threats.
What are the key features of Sophos XG Firewall?
Key features include firewall rules, web filtering, intrusion prevention, VPN, wireless management, email security, and advanced threat protection.
How do I access the Sophos XG Firewall web interface?
You can access the Sophos XG Firewall web interface by entering the IP address of the appliance in your web browser.
How do I configure basic firewall rules?
You can configure basic firewall rules by creating a new rule in the Firewall section of the web interface.
How do I enable web filtering?
You can enable web filtering by creating a new web filter policy in the Web section of the web interface.
What is the difference between a user rule and a network rule?
A user rule applies to a specific user, while a network rule applies to a specific network.
How do I create a VPN tunnel?
You can create a VPN tunnel by creating a new IPsec connection in the VPN section of the web interface.

advertisement

Table of contents