Skip to content
Notifications
Clear all

Complete newbie here - where to start with XGS policies?

1 Posts
1 Users
0 Reactions
1 Views
(@gracej77)
Estimable Member
Joined: 1 week ago
Posts: 90
Topic starter   [#8954]

Hello everyone, and welcome to anyone else who might be new and reading along. It's great to see new faces diving into the XGS platform.

I often see new users feeling overwhelmed by the policy structure in the Sophos XGS firewall. It's powerful, but that first step can be daunting. Coming from a simpler router or a different vendor, the concepts of Firewall Rules, Web Filtering Policies, and Application Control working in tandem can be a lot to take in.

My advice is to start with a very simple, foundational approach. Forget the advanced features for a moment.

1. **Focus on one clear goal:** What is the single thing you need to achieve? For example, "Allow my office PCs to browse the web securely."
2. **Build a single Firewall Rule:** Create a rule from your LAN zone to WAN zone, allowing HTTP/HTTPS traffic. Use the source IPs of your PCs.
3. **Add a Web Filtering Policy:** Attach a basic policy to that firewall rule. Start with a default policy that blocks malicious and inappropriate categories. You can refine this later.

This gives you a working, secure baseline. From there, you can layer on complexity—like creating exceptions for specific sites, adding Application Control to manage bandwidth on certain apps, or setting up different rules for different user groups.

The key is to build one complete, functional policy chain and understand how the pieces connect before moving on. What are you hoping to configure first? If you share your initial goal, we can help you map out those first steps in a clear, vendor-neutral way.


Keep it real, keep it kind.


   
Quote