Jump to content

Recommended Posts

Posted

Hello all,

 

We've been asked to assist with installing the new cloud (i.e. not Sophos Central) version of Sophos antivirus into a secondary school using a Smoothwall appliance for filtering and monitoring.

 

The web-installer fails, and looking at the logs it fails because the root certificates are invalid when connecting to Sophos' servers to actually download the installer. Sure enough, when we bypass HTTPS inspection on the Smoothwall for the workstation we're testing, the installer downloads and the process completes as expected.

 

However, we can't disable HTTPS inspection for the whole network, even if just for the duration of the install (for obvious reasons).

 

So instead, we added the URL's on this list: https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/DomainsPorts.html

 

To a category, and created a bypass for HTTPS content inspection based on this. This does not work. When we monitor web filter traffic from our IP (to make sure that the URL's match the ones we added to the bypass) we can see URL's that should match the rule for HTTPS inspection bypass. I was wondering if it's because I cannot add wildcard-type subdomains to the category on Smoothwall (unless there's a trick that evades me), despite the Sophos guide requiring them?

 

If anyone has solved this issue, I'd be grateful for any pointers. I know that Smoothwall and Sophos are popular within schools, so hopeful somebody else has trodden this path and resolved the issue!

 

Thank you!

Posted

As far as I remember Smoothwall automatically creates wildcards for incomplete domain entries. So "*.cloudfront.net" can just be entered as "cloudfront.net" to allow/block/etc any URL that ends in "...cloudfront.net"

Also make sure the Do not Inspect policy is above any Decrypt and Inspect or Validate Certificate ones, as S-wall process policies top to bottom.

 

We use Sophos Central, but having a whitelist policy for the handful of required URLS seems to have worked fine.

Posted

Had the same issue, just quick allow on smoothwall the following domains,

 

 

 

Sophos Central Admin domains

You must allow these domains and ports through your firewalls and proxies for your protection to work correctly.

 

If you're a partner managing accounts for customers, you must do this for each customer's firewall or proxy.

 

central.sophos.com

cloud-assets.sophos.com

sophos.com

downloads.sophos.com

Note

If your proxy or firewall supports wildcards, you can use the wildcard *.sophos.com to cover these addresses.

Then enter the following non-Sophos addresses.

 

az416426.vo.msecnd.net

dc.services.visualstudio.com

*.cloudfront.net

You must also review the other sections in this page and allow the appropriate domains and ports for all your licenses.

 

If you're a partner managing accounts for customers, you must do this for each customer's firewall or proxy, matching each customer's licenses.

 

Endpoint domains

If your proxy or firewall supports wildcards, use the following wildcards to cover these Sophos endpoint domains.

 

*.sophos.com

*.sophosupd.com

*.sophosupd.net

*.sophosxl.net

Then enter the following non-Sophos addresses.

 

ocsp2.globalsign.com

crl.globalsign.com

If your proxy or firewall doesn't support wildcards, you must identify the exact Sophos endpoint domains you need, then enter them manually.

 

To identify the server address that Sophos Management Communication System uses to communicate with Sophos Central Admin securely, do as follows:

 

Open SophosCloudInstaller.log. You can find it in the following locations:

Windows 2008 R2 and later: C:\Documents and Settings\All Users\Application Data\Sophos\CloudInstaller\Logs

 

Windows 7 and later: C:\ProgramData\Sophos\CloudInstaller\Logs

 

Look for the following lines:

line starting Model::server value changed to:

line starting Opening connection to

They should have a value that looks like this dzr-api-amzn-eu-west-1-9af7.api-upe.p.hmr.sophos.com.

 

You must add this address and the following addresses to your firewall or proxy allow list.

 

dci.sophosupd.com

d1.sophosupd.com

d2.sophosupd.com

d3.sophosupd.com

dci.sophosupd.net

d1.sophosupd.net

d2.sophosupd.net

d3.sophosupd.net

t1.sophosupd.com

sdu-feedback.sophos.com

sophosxl.net

4.sophosxl.net

samples.sophosxl.net

cloud.sophos.com

id.sophos.com

central.sophos.com

downloads.sophos.com

amazonaws.com

*.hydra.sophos.com

If you want to be more specific about the domains you allow for hydra.sophos.com you can use the following domains.

 

*.mcs2-cloudstation-eu-west-1.prod.hydra.sophos.com

*.mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com

*.mcs2-cloudstation-us-east-2.prod.hydra.sophos.com

*.mcs2-cloudstation-us-west-2.prod.hydra.sophos.com

You must also add the following non-Sophos domains. You must not use wildcards for these domains.

 

ocsp.globalsign.com

ocsp2.globalsign.com

crl.globalsign.com

crl.globalsign.net

ocsp.digicert.com

crl3.digicert.com

crl4.digicert.com

Note

Some firewalls or proxies show reverse lookups with *.amazonaws.com addresses. This is expected as we use Amazon AWS to host several servers. You must add these URLs to your firewall or proxy.

Endpoint ports

You must add the following ports.

 

80 (HTTP)

443 (HTTPS)

AD Sync

If you're using the Active Directory service, you must also add the following pre-signed s3 domains:

 

tf-presigned-url-eu-west-1-prod-*-bucket.s3.eu-west-1.amazonaws.com

tf-presigned-url-eu-central-1-prod-*-bucket.s3.eu-central-1.amazonaws.com

tf-presigned-url-us-east-2-prod-*-bucket.s3.us-east-2.amazonaws.com

tf-presigned-url-us-west-2-prod-*-bucket.s3.us-west-2.amazonaws.com

If your proxy or firewall supports wildcards you can add the following wildcards:

 

*.s3.eu-west-1.amazonaws.com

*.s3.eu-central-1.amazonaws.com

*.s3.us-east-2.amazonaws.com

*.s3.us-west-2.amazonaws.com

Intercept X Advanced with EDR

Note

Add the domains and ports listed in Endpoint domains and Endpoint ports before adding the domains listed below.

If you have an Intercept X Advanced with EDR license, you must also add the following domains:

 

tf-edr-message-upload-eu-central-1-prod-bucket.s3.amazonaws.com

tf-edr-message-upload-eu-west-1-prod-bucket.s3.amazonaws.com

tf-edr-message-upload-us-east-2-prod-bucket.s3.amazonaws.com

tf-edr-message-upload-us-west-2-prod-bucket.s3.amazonaws.com

live-terminal-eu-west-1.prod.hydra.sophos.com

live-terminal-eu-central-1.prod.hydra.sophos.com

live-terminal-us-west-2.prod.hydra.sophos.com

live-terminal-us-east-2.prod.hydra.sophos.com

*.mcs-push-server-eu-west-1.prod.hydra.sophos.com

*.mcs-push-server-eu-central-1.prod.hydra.sophos.com

*.mcs-push-server-us-west-2.prod.hydra.sophos.com

*.mcs-push-server-us-east-2.prod.hydra.sophos.com

  • Thanks 1
Posted

Thank you both.

 

The above instructions, in essence are what I have done.

 

I wasn't sure if removing the *. from the Sophos instructions (as is required to save the category in Smoothwall) would in effect apply a wildcard for hosts and subdomains, or it it would instead refer only to the specific URL entered.

 

My rule sits atop all the other inspection policies, so I must have made a mistake. I'll check my work.

 

Thanks again!

Posted
It may be getting caught in some other part of the guardian policies. Maybe try putting them in a we filtering whitelist under Guardian>Policies.
Posted

Thank you.

 

I originally started that before realising it was HTTPS inspection causing the issue. I had the category created and placed into the web filter as an exceptions list.

 

I must have made a mistake - need to check my work.

 

Thanks for all your help.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...