I have confirmed that the latest Sophos Firewall SFOS version 20.0.0 GA-Build222 is using open source Snort as its Intrusion Prevention System (IPS)

Turritopsis Dohrnii Teo En Ming <[email protected]> Sun, 19 Nov 2023 22:00:37 +0000
Newsgroups gmane.os.freebsd.chat
Message-ID <ra7TtzURiv_jBVxXtf_yy36mCe1dx9y2ER3SP0NUWG_8d8AjgP3CaWngcxSplBcP27WhqT44UXv6tSYyR1QXcv4toLXLtXMA23Qr2qPCzMs=@protonmail.com>
Subject: I have confirmed that the latest Sophos Firewall SFOS version 20.0=
.0 GA-Build222 is using open source Snort as its Intrusion Prevention Syste=
m (IPS)

Good day from Singapore,

I have started installing Sophos Firewall SFOS version 20.0.0 GA-Build222 o=
n my Intel Celeron J3160 (4 GB DDR3L RAM + 64 GB SSD) on 16 Nov 2023 Thursd=
ay at 11.00 PM. Initially I had wanted to install Sophos Firewall on my new=
est Intel Celeron J4125 (8 GB DDR4 + 64 GB SSD) but the Linux Kernel versio=
n 4.14.302 wasn't able to detect Intel Ethernet Controller I225-V 2.5 GbE n=
etwork interface cards. To workaround the problem, I had to install pfSense=
 firewall version 2.7.0 on my Intel Celeron J4125 firewall appliance and th=
en install Sophos Firewall on my Intel Celeron J3160 firewall appliance. Bo=
th pfSense and Sophos Firewall use open source Snort as its Intrusion Preve=
ntion System (IPS).

When I was installing Sophos Firewall on my Intel Celeron J3160 firewall ap=
pliance, I opened up the terminal and traversed the Linux filesystem. I saw=
 the directory snort inside the /etc/ directory. This confirmed that the la=
test version of Sophos Firewall is indeed using open source Snort as its In=
trusion Prevention System (IPS).

Regarding my Sophos Firewall, I have only performed a Basic Setup/Configura=
tion at the moment. But I have also turned on IPS and ensured that Admin Se=
rvices (HTTPS and SSH) are restricted to the LAN zone only. Further explora=
tion of the (1) network interfaces and (2) firewall policies/rules inside S=
ophos Firewall will be done later when I have more time.

It is good to know that major firewall vendors like Sophos and pfSense (net=
gate) are using open source Snort as its Intrusion Prevention System (IPS).=
 This goes to show that Snort is a rock solid and top notch IPS which is we=
ll supported by the world's networking leader Cisco.=20

I am still unable to determine if Fortigate firewalls are using Snort as it=
s IPS because Fortinet has extensively modified the Linux operating system =
for its FortiOS.

I have finished installing Sophos Firewall (Basic Setup and Configuration o=
nly) on my Intel Celeron J3160 firewall appliance on 17 Nov 2023 Friday at =
1.00 AM. I have managed to sleep at about 2.00 AM and woke up in the mornin=
g at about 7.00 AM on 17 Nov 2023 Friday.

I do notice that my Sophos Firewall is a bit slow and lags. Perhaps it is b=
ecause my Intel Celeron J3160 firewall appliance only has 4 GB of RAM. I wi=
ll need to increase the amount of memory in the future.

Fortigate, pfSense and Sophos firewalls support SNMP.

Regards,

Mr. Turritopsis Dohrnii Teo En Ming
Targeted Individual in Singapore
Blogs:
https://tdtemcerts.blogspot.com
https://tdtemcerts.wordpress.com
GIMP also stands for Government-Induced Medical Problems.




Sent with Proton Mail secure email.