Hey everyone! I've been deep in the sandbox this week testing a specific incident response workflow, and I wanted to share the detailed steps I took (and learned from) for isolating a compromised host using the Sophos XGS firewall and its built-in NAC functionality. This came up after a simulated phishing campaign in our test environment went a bit too "well" 😅.
The scenario: We had a test machine (Windows 10) that got flagged by our EDR for beaconing behavior. The immediate goal was to contain it at the network level without physically disconnecting the machine, preventing any potential lateral movement or data exfiltration. Here's the step-by-step process I followed on the XGS:
**1. Initial Identification & NAC Policy Creation:**
* First, I used the Live User/Device view in the XGS to find the host's IP and MAC address. The key here is to use the MAC, as IPs can change.
* In the **Firewall NAC > Static Hosts** section, I created a new entry for the compromised host, defining it by its MAC address and giving it a recognizable name (e.g., `QUARANTINE_Host_ABC`).
* Then, I created a new **User/Identity Policy** under the NAC section. I assigned the `QUARANTINE_Host_ABC` static host to a new, dedicated "Quarantine" user group I set up called `Quarantined_Hosts`.
**2. Building the Quarantine Security Zone:**
* This was the crucial part. I created a new **Firewall Zone** (let's call it `QUARANTINE_ZONE`) with very restricted settings.
* Under **Firewall Rules**, I made rules for this zone that ONLY allowed necessary traffic (like updates for the EDR agent and DNS for resolution) and explicitly blocked ALL other outbound/inbound traffic. The goal is to allow the host to "phone home" to our security tools for remediation but nothing else.
* Most importantly: I did *not* assign any physical interface to this zone. It's a logical zone used for policy enforcement.
**3. Applying Isolation with NAC Policy Rules:**
* Back in **Firewall NAC > NAC Policy**, I added a new policy.
* I set the **Source** to the `Quarantined_Hosts` user group.
* For **Network**, I assigned the new `QUARANTINE_ZONE`. This is the magicβit forces any traffic from that identified host (via the Static Host -> User Group mapping) to be evaluated against the ultra-restrictive firewall rules of the quarantine zone, regardless of which physical port or SSID it's connected to.
**4. Testing & Observations:**
* Once applied, the host immediately lost general internet and internal network access, except for the specific allow rules I defined. The firewall logs clearly showed the traffic being matched to the `QUARANTINE_ZONE` rules.
* I could then trigger a scan from our EDR console, and see the allowed traffic pass through, confirming the host was contained but still manageable.
**Pitfalls & Lessons Learned:**
* **Timing is critical:** The NAC policy applies to *new* sessions. Existing connections from the host might persist until they time out or are manually reset. In a real incident, I'd combine this with a firewall rule to drop existing sessions immediately.
* **Wireless & Dynamic IPs:** This MAC-based approach works great for wired hosts. For wireless, ensuring the XGS is the DHCP server (or has visibility into DHCP leases) is key for reliable host identification.
* **Automation Potential:** While I did this manually, the entire process screams for automation via the Sophos Central API. You could theoretically have your EDR trigger a script to create the static host and apply the NAC policy automatically upon a high-severity alert.
Has anyone else set up a similar automated containment workflow? I'm particularly curious if you've integrated the XGS NAC with an external ticketing system or SOAR platform to log the actions. Also, any thoughts on using User/Device Awareness vs. straight MAC addresses for more dynamic environments?
β Emma
If it's not measurable, it's not marketing.
Interesting approach, but you're putting a lot of faith in the firewall's ability to correctly identify that host via MAC in real-time, especially if you're dealing with a virtual environment or certain docking stations. What was your observed delay between policy application and the host actually being moved into the quarantine zone? In my experience, that lag can be the gap where something slips through.
Also, does this method hold if the compromised host is already on a network that isn't using 802.1X? Or are you assuming a specific NAC deployment model that wasn't mentioned?
Data skeptic, not a data cynic.