
Hello everyone! Continuing with this I want to tell you more about the functionality offered by the Sophos XG Firewall solution and introduce you to the web interface. Commercial articles and documents are good, but it's always interesting to see how the solution looks in real life. How is everything organized? Let's start the review.
This article will show the first part of the Sophos XG Firewall functionality — 'Monitoring and Analytics'. A complete overview will be released as a series of articles. We will base our journey on the web interface of Sophos XG Firewall and the licensing table.

Security Management Center
Now, we've launched the browser and opened the web interface of our NGFW, where we see a prompt to enter the username and password to access the admin panel.

We enter the username and password that we set during the initial activation and land in our management center. It looks like this.

Almost all of these widgets are clickable. You can drill down into an incident and see the details.
Let's break down each of the blocks, starting with the System block.
System Block

This block displays the real-time status of the machine. Clicking on any of the icons will take us to a page with more detailed information about the system's status.

If there are issues in the system, this widget will signal about it, and you can check the reason on the information page.

By navigating through the tabs, you can get more information about various aspects of the firewall's operation.



Traffic Insight Block

This section gives us an overview of what is currently happening in our network and what has occurred in the last 24 hours. The top 5 web categories and applications by traffic, network attacks (IPS module triggering), and the top 5 blocked applications.
Additionally, the section Cloud Applications deserves separate attention. Here, you can see the presence of applications in the local network that utilize cloud services. Their total number, incoming and outgoing traffic. Clicking on this widget will take us to the information page for cloud applications, where we can look in more detail at which cloud applications are in the network, who is using them, and traffic information.

User & Device Insights Block

This section displays information about users. The top line shows us information about infected user computers, collecting data from the Sophos antivirus and sending it to the Sophos XG Firewall. Based on this information, the Firewall can disconnect a user's computer from the local network or network segment at the L2 level by blocking all connections to it in case of infection. More details about Security Heartbeat were provided in . The next two lines cover application control and cloud sandboxing. Since this is a separate functionality, it will not be discussed in this article.
Attention should be paid to the two lower widgets. These are ATP (Advanced Threat Protection) and UTQ (User Threat Quotient).
The ATP module blocks connections to C&C command servers of botnet networks. If a device in your local network becomes part of a botnet, this module will notify you and prevent it from connecting to the command server. It appears as follows


The UTQ module assigns a security index to each user. The more a user attempts to visit prohibited sites or run unauthorized applications, the higher their rating becomes. Based on this data, training can be conducted for such users in advance, without waiting for their computer to be infected with malware. It looks like this

Next is a section with general information about active firewall rules and hot reports that can be quickly downloaded in PDF format.

Let’s move on to the next section of the menu — Current activities
Current activities

We will start the overview with the Live users tab. On this page, we can see who among the users is currently connected to the Sophos XG Firewall, the authentication method, the machine's IP address, the connection time, and the traffic volume.
Live connections

This tab displays active sessions in real-time. This table can be filtered by applications, users, and client machine IP addresses.
IPsec connections

This tab displays information about active IPsec VPN connections.
Remote users tab
In the Remote users tab, there is information about remote users who have connected via SSL VPN.

Also, in this tab, you can view real-time traffic by users and forcibly disconnect any user.
We'll skip the Reports tab, as the reporting system in this product is very extensive and requires a separate article.
Diagnostics

The page immediately opens with various troubleshooting utilities, including Ping, Traceroute, Name lookup, and Route lookup.
Next is a tab with system graphs displaying real-time hardware and port load.
System graphs

Then there's a tab where you can check the category of a web resource.
URL category lookup

The next tab, Packet capture, essentially acts like tcpdump embedded in the web interface. You can also write filters.
Packet capture


Interestingly, packets are converted into a table where you can toggle additional columns of information. This functionality is very convenient for troubleshooting network issues, as you can quickly understand which filtering rules were applied to real traffic.

In the Connection List tab, you can view all existing connections in real time along with their information.
Connection List

Conclusion
This concludes the first part of our review. We've only covered a small portion of the available functionality and haven't touched on the security modules at all. In the next article, we'll discuss the built-in reporting functionality and firewall rules, their types, and purposes.
Thank you for your time.
If you have any questions regarding the commercial version of XG Firewall, you can contact us — the company , the distributor of Sophos. Just write in a free form to .
Source: habr.com
