NOTE: due to our forum not be able to display more than 20 images, I'll be splitting this into 3 post...
part 1/3:
https://www.istorya.net/forums/networ...l#post17936265
part 2/3:
https://www.istorya.net/forums/networ...l#post17936278
part 3/3:
https://www.istorya.net/forums/networ...l#post17936304
greetings to all!
I would like to share my experience with Sophos UTM 9.
This will cover the installation process, and a bit of configuration and a little sample of QOS for gaymes like dota2 and crossfire ph.
You may consider this a mini guide/reference!
credits goes to various websites.
note(s) and disclaimer:
- very long post with pics and vidz!
- this is not for the faint of heart!
- prepare paracetamol, dolfenal or equivalent
- I'm not an affiliate of Sophos.
- I may not able to reply asap or help you with your problem.
sophos website link:
https://www.sophos.com/en-us/product...e-edition.aspx
wikipedia link:
https://en.wikipedia.org/wiki/Sophos
I am now using and evaluating the "FREE" Sophos UTM 9 'home edition' as my current firewall/router + anti-virus web scanner and I'm moving away from pfSense as it seems to be too hard to configure for my taste..., or I'm just too dumb using it.
Sophos UTM 9 is an enterprise grade UTM (Unified Threat Management) and the best part of it is that they offer "free" for home use!, although the limitation I see from this is just "LIMITED" to 50 IP's. So for regular home use, I believe you will not be able to reach 50 IP's. and take good note..., You need to get a free lincense from their website.
let's start with what we need:
- 2x lan card/ethernet card/NIC
- p4 or atom or recent computer (if you know how to virtualize then go for it)
- 1gb ram minimum? (more recommended)
- 20gb hdd? (more recommended)
- Sophos UTM 9 iso (reference filename: asg-9.314-13.1.iso)
- (usb/flash drive) or (dvd/cdrom + blank media)
Download the iso from Sophos website and select "Sophos UTM 9" and not the new one which is "XG UTM" and be sure NOT to select hardware type ISO download but the software one or appliance.
Be sure to take note the MAC address of both NICs and their physical locations.
Transfer ISO to Flash drive or Burn to disk (your choice).
Turn on the test computer and boot our Sophos installer.
note: my installation is virtualized using:
- gentoo linux + kvm as my host hypervisor (console only!)
- 2x virtual cpus
- 2gb ram
- 25gb raw partition (via virtio)
- 2x intel lan nics being passthrough to the guest via virtio
note:
- installer might complain if you don't meet its minimum requirements, specially with 2x NICS.
- good thing about the installation media is that it is VM friendly. it detects that its inside a VM!
!!!INSTALLATION!!!
note: I made a temporary VM so that I can do screenshots (for reference) as I was not able to do the actual screenshots that I made..., but this is almost the exact things I did, except for the virtual NICs you'll see from the screenshot(s)
This is the first thing you'll see..., press 'enter'
Some info..., select 'Start' and press 'enter'
Hardware detection phase...
Result from detection phase...
take note that the HDD and NICs here are just dummies
Keyboard selection (self explanatory...)
Timezone (self explanatory...)
Date and Time
note that if your BIOS is local time, untick/uncheck "host clock is UTC"
Very important!!!
the selection here will become your internal "LAN" and the other one will be "WAN"
this will be where you will be 'logging-in' from your UTM
Provide your IP range... (I used 10.10.10.0/26)
I'm trying to limit my network to just around 50 connections/IP's
you can still use the famous 192.168.x.1 here and if you do, netmask should be 255.255.255.0 and do not copy what I have there
note: just leave the gateway blank for now
Since my environment is 64bit capable, I chose to go with the 64bit kernel
kindly read some explanations here
READ and select "Yes"
READ and select "Yes"
note: there seems to be no option for custom partition layout here...
Some info...
And take note here, specially with the "https://x.x.x.x:4444"
this address will be the one you will be 'logging-in' afterwards...
and then hit reboot...
You'll see this when booting your hardware after the first boot
This blackish screen will tell you something again...
Open now from another computer and type in the "https" sequence...
click the small advanced word and click "proceed to x.x.x.x (unsafe)