Sophos XG Firewall Web Interface Reference and Admin Guide v16.5

Add to My manuals
627 Pages

advertisement

Sophos XG Firewall Web Interface Reference and Admin Guide v16.5 | Manualzz

2. Enter the details.

Name

Displays the name of the Application Filter Category or Application.

Traffic Shaping Policy

Select a policy or click Create new to create a new traffic shaping policy for the application/ application category.

Traffic Shaping policy allocates and limits the bandwidth usage of the user, web category, application category.

3. Click Save.

Wireless

Wireless Protection allows you to configure the following:

Wireless Networks

: Create and manage Wireless Networks.

Mesh Networks

: Create and manage Mesh Networks.

Access Points

: Provides an overview of the access points known to the device.

Access Point Groups

: Allows you to organize access points in groups.

Hotspots

: Add/remove Hotspots and apply filtering policies.

Hotspot Voucher Definition

: Manage different voucher definitions for Hotspot access vouchers.

Rogue AP Scan

: Schedule scanning to discover authorized APs and rogue APs.

Wireless Client List

The Wireless Client List page displays a live snapshot of currently managed APs, broadcasted SSIDs (wireless networks), wireless clients connected through SSID to AP and mesh networks.

Show by SSID/Show by AP

The administrator can filter currently connected clients by Access Point or SSID

The following details is displayed each SSID/AP: name, IP address, MAC address, signal, last data transfer rate, connection time, frequency, vendor.

| Protect | 154

Figure 161: Wireless Client List

Wireless Networks

The Wireless Networks menu allows managing the wireless networks connected to the device.

Note: You can also view the wireless network status on the Protect > Wireless > Wireless Client List

The page provides a list of all configured wireless networks along with their name, SSID, status, client traffic mode, encryption mode used and frequency band.

Figure 162: Wireless Networks List

Add a New Wireless Network

This page describes how to add a new wireless network.

Newly created wireless networks can be used in definitions for access points and access point groups.

1. Go to Protect > Wireless > Wireless Networks and click the Add button.

2. Specify the General Settings settings.

Name

Specify a descriptive name for the network.

Description

Enter a description for the wireless network that helps you to identify it.

SSID

Enter the Service Set Identifier (SSID) for the network which will be seen by clients and allow them to identify the wireless network. The SSID may consist of 1-32

ASCII printable characters

.

Security Mode

Select a security mode from the drop-down list.

Default: WPA 2 Personal.

Note: We recommend to use WPA2. For security reasons, we recommend not to use

WEP unless there are clients using your wireless network that do not support one of the other methods.

When using an enterprise authentication method, you also need to configure a RADIUS server on the Configure > Authentication > Servers page. As NAS ID of the RADIUS server enter the wireless network name.

Note: Sophos XG Firewall supports the IEEE 802.11r standard in WPA2 (PSK/

Enterprise) networks to reduce roaming times. Clients also need to support the IEEE

802.11r standard.

Passphrase/PSK (available only if WPA Personal, WPA2Personal, or WPA2/WPA Personal

security mode is selected)

Specify the passphrase to protect the wireless network from unauthorized access and repeat it in the

Confirm Passphrase/PSK field. The passphrase may consist of 8-63 ASCII printable characters.

Key (available only if WEP Open security mode is selected)

Specify a WEP key that consists of exactly 26 hexadecimal characters.

Client Traffic

From the dropdown list select how the wireless network is to be integrated into your local network.

Available options:

• Separate Zone

• Bridge to AP LAN

• Bridge to VLAN

Default: Separate Zone.

Separate Zone

The wireless network is handled as a separate network, having an IP address range of its own. Using

this option, after adding the wireless network, proceed as described in the chapter

Next Steps for

Separate Zone Networks

.

Note: When switching an existing Separate Zone network to Bridge to AP LAN or

Bridge to VLAN, a previously configured WLAN interface will be deleted.

Zone

From the dropdown list select a zone where the wireless network should be broadcast.

| Protect | 155

Default: WiFi.

IP Address

Assign an IP address to the wireless network.

Netmask

Select a subnet mask for the IP address.

Bridge to AP LAN

You can bridge a wireless network into the network of an access point, which means that wireless clients share the same IP address range. Using this option, after adding the wireless network, proceed as described in the chapter

Next Steps for Bridge to AP LAN Networks

.

Bridge to VLAN (not available for local WiFi devices)

You can decide to have this wireless network's traffic bridged to a VLAN of your choice. This is useful when you want access points to be in a common network separate from the wireless clients.

Bridge to VLAN ID

Specify the VLAN ID of the network that the wireless clients should be part of.

Client VLAN ID (only available with an enterprise security mode)

Select how the VLAN ID is defined.

Static: Uses the VLAN ID defined in the Bridge to VLAN ID field.

RADIUS & Static: Uses the VLAN ID delivered by your RADIUS server: When a user connects to one of your wireless networks and authenticates at your RADIUS server, the

RADIUS server tells the access point what VLAN ID to use for that user. Thus, when using multiple wireless networks, you can define per user who has access to which internal networks.

If a user does not have a VLAN ID attribute assigned, the VLAN ID defined in the Bridge to

VLAN ID is used.

| Protect | 156

Figure 163: Add Wireless Network

3. Specify the Advanced Settings.

Encryption (available only if the WPA, WPA2, or WPA2/WPA encryption mode is selected)

Select an encryption algorithm, which can be AES, TKIP or TKIP&AES.

Note: For security reasons and better performance, we recommend you to use AES.

Frequency Band

Access points assigned to this wireless network will transmit on the selected frequency band(s).

The 5 GHz band generally has a higher performance, lower latency, and is typically less disturbed.

Hence it should be preferred for e.g. VoIP communication.

Time-based Access

Select this checkbox to enable the wireless network access according to a time schedule.

Select Active Time (available only if Time-based Access is selected)

Select a schedule definition which determines when the wireless network is enabled. You can add a new schedule definition by clicking Add New Item .

Client Isolation

Clients within a network usually can communicate with one another. If you want to prevent this, for example in a guest network, select Enabled from the drop-down list.

Hide SSID

If you want to hide the wireless network's SSID, select the Enable checkbox. Please note that this is not a security feature.

Fast Transition (available only if WPA2 Personal/Enterprise security mode is selected)

Wireless networks with WPA2 security use the IEEE 802.11r standard. If you want to prevent this, select Disabled from the drop-down list.

MAC Filtering

To restrict the MAC addresses allowed to connect to this wireless network, select Blacklist or

Whitelist. With Blacklist, all MAC addresses are allowed except those listed on the MAC List.

With Whitelist, all MAC addresses are prohibited except those listed on the MAC List.

MAC hosts added under System > Hosts and Services > MAC Host will be displayed in the MAC

List.

| Protect | 157

Figure 164: Wireless Network Advanced Settings

4. Click Save.

Next Steps for Separate Zone Networks

This page describes how to configure a seperate zone network.

advertisement

Key Features

  • Firewall rules
  • Web filtering
  • Intrusion prevention
  • VPN
  • Wireless management
  • Email security
  • Advanced threat protection

Related manuals

Frequently Answers and Questions

What is the purpose of Sophos XG Firewall?
Sophos XG Firewall is a network security appliance designed to protect your network from threats.
What are the key features of Sophos XG Firewall?
Key features include firewall rules, web filtering, intrusion prevention, VPN, wireless management, email security, and advanced threat protection.
How do I access the Sophos XG Firewall web interface?
You can access the Sophos XG Firewall web interface by entering the IP address of the appliance in your web browser.
How do I configure basic firewall rules?
You can configure basic firewall rules by creating a new rule in the Firewall section of the web interface.
How do I enable web filtering?
You can enable web filtering by creating a new web filter policy in the Web section of the web interface.
What is the difference between a user rule and a network rule?
A user rule applies to a specific user, while a network rule applies to a specific network.
How do I create a VPN tunnel?
You can create a VPN tunnel by creating a new IPsec connection in the VPN section of the web interface.

advertisement

Table of contents