Sophos Firewall Initial Setup - 夜莺博客

Sophos Firewall Initial Setup

原文:Sophos Firewall Initial Setup — theDXT (Daniel Keer)

Before you can start using a Sophos firewall, you must complete the initial setup.

In this post, I will show you step by step, how to complete the initial setup of a virtual SFOS (Sophos Firewall Operating System). The process will be similar on a physical Sophos firewall.

What you need before you start

The console walkthrough is the quickest part of the job; almost every real-world delay comes from something that was not ready beforehand. Have these in place first:

  • Console access - a VM console session, or a serial/USB console cable for a physical appliance. This is your recovery path: if the management IP is wrong, the web UI is unreachable and the console is the only way back in.
  • Internet access on the WAN port - SFOS 22 and newer requires an internet connection during setup for firmware and licensing. A stale WAN link is the number one cause of a setup wizard that hangs at the registration step.
  • Licence or serial number - a purchased serial, or the ability to start a trial. On SFOS 22+, registration is mandatory for a virtual instance, so decide which you will use before you begin.
  • Planned addressing - the LAN IP/mask for the firewall, the WAN addressing mode (DHCP or static), and a DNS server. Write them down; the wizard gives you no place to keep notes.
  • A maintenance window - the wizard reboots and applies a configuration at the end, so nothing behind the firewall is reachable until it finishes.

Prerequisites

  • Internet access.
  • Console access.

Understanding the factory defaults

SFOS ships with a predictable starting state, and knowing it saves a lot of guessing:

  • PortA defaults to a LAN role with the static address 172.16.16.16/24. It is your management interface, and the web UI lives on it.
  • PortB defaults to the WAN role using DHCP, which is why the firewall usually reaches the internet the moment you plug it into a home or branch router.
  • Ports C and above are unassigned until you map them; on a virtual instance you also need to map virtual NICs to ports in the hypervisor, which is covered in Sophos Firewall interface mapping on vSphere.
  • The admin password is admin from the console - and it is changed in the first wizard page. The web UI is served on HTTPS port 4444, not 443.
  • GuestAP exists as a default wireless interface on many builds and is worth removing on a virtual deployment that will never host an access point - see removing the default GuestAP interface.

The Process

  • Connect to the SFOS VM console.
  • Enter the admin password.

The default admin password is admin.

Image 1

  • Review the End User Terms of Use and accept them if you agree.

Image 2

  • Enter 1 for Network Configuration Menu.

Image 3

  • Enter 1 for Interface configuration.

Image 4

SFOS will show the current IP address for PortA. The default IP address for PortA is 172.16.16.16.

Image 5

  • Press Enter to continue.

SFOS will display the current IP address for PortB. The default setting for PortB is DHCP.

Image 6

  • Press Enter to continue.
  • Press Y to set the IPv4 Address for PortA.

Image 7

  • Enter the IP address you would like to use, then press Enter.

Image 8

  • Enter a new netmask if needed, then press Enter.

Image 9

  • Once Changing IP Address of the Device says Done, press Enter.

Image 10

  • Press N to skip the IPv6 address setup.

Image 11

At this point the console work is done and you can move to the browser. Note that the console writes the change to a staging area - the address only becomes the permanent management address once the web wizard finishes, which is one reason not to interrupt the wizard partway through.

The web setup wizard

  • In a web browser, go to the IP you just set using HTTPS on port 4444.
  • Review and Sophos End User Terms of Use. If you agree, select I accept and click Start setup.

Image 12

The first item we need to configure is a new password for the admin account. The password must be at least ten characters, one uppercase letter, one lowercase letter, one number, and one special character.

  • Type the new admin password and click Continue.

Image 13
If you leave Install the latest firmware automatically selected, and there’s a new firmware, you will need to install it.

Image 14

Next, we configure the secure storage master key. The secure storage master key is unique to your firewall and provides additional protection for the passwords and account details stored in the firewall configuration. You will not be able to restore a backup without knowing the master key.

The master key must be at least twelve characters, one uppercase letter, one lowercase letter, one number, and one special character.

  • Type the secure storage master key.

Image 15

  • Save the master key in a secure location and click Continue.

Image 16

When configuring a virtual SFOS running version 22 or newer, an internet connection is now mandatory. This was optional in SFOS versions prior to 22.

  • Configure an internet connection.

Image 17

  • Enter your firewall’s FQDN (fully qualified domain name) and select its time zone.

In my example, I will use the FQDN DXT-SF-FW01.dxt.local and set the time zone to America/Edmonton.

Image 18

  • Enter your serial number or start a trial.

When using a virtual SFOS running version 22 or newer, registering the firewall is now mandatory. In previous versions of SFOS, you could skip the registration.

Make sure you enter the correct serial number, as it can not be changed later.

Image 19

  • Review the licensing information and click Continue.

Image 20

  • Select the LAN port to use.

In my example, I will leave the LAN port set to PortA.

  • Configure the gateway mode.

Most deployments use route mode (gateway mode).

In my example, I will be using route mode.

  • Change the firewall’s IP address if needed.

Because we set the firewall’s IP address using the console, we can skip it.

  • Choose whether to Enable DHCP.

In my example, I will not be using DHCP on the Sophos firewall, as I already have a DHCP server.

  • Once you have configured the LAN settings, click Continue.

Image 21

  • Select the desired Network protections, then click Continue.

In my example, I will enable all the network protections.

Image 22

  • Type a recipient email address for firewall notifications and backups.
  • Type a sender email address for firewall notifications and backups.
  • Choose if you want the SFOS configuration backup emailed weekly.
  • Type a password to encrypt backups.

The backup encryption password must be twelve characters.

  • Once you have configured the notifications and backups settings, click Continue.

Image 23

  • Review the SFOS configuration summary. If everything looks good, click Finish.

Image 24

  • Wait while the Sophos firewall applies the configuration.

Image 25

  • Once the configuration is applied, you can login to SFOS with the admin account and the password you configured.

Image 26

That’s all it takes to complete the initial setup on a virtual SFOS (Sophos Firewall Operating System).

The steps that actually matter later

The wizard is largely mechanical, but three of its pages have consequences that only show up months afterwards:

  • Secure storage master key. It protects every password and credential stored in the configuration - VPN pre-shared keys, LDAP bind passwords, admin hashes. Without it, a restored backup is useless, which means a backup you cannot decrypt is not a backup. Store it in a password manager, not in the same place as the backups.
  • Backup encryption password. The weekly emailed backup is only as good as this password, and it is the second secret you must keep. Note that changing it later does not retroactively re-encrypt historical files.
  • Serial number. It cannot be changed after registration. A typo here means the licence is bound to a device that does not exist, and correcting it requires a licence transfer through Sophos support.

Post-setup checklist

Once you can log in to the dashboard, do not hand the firewall over to production traffic before working through this list:

# Confirmation you are on the expected build
System > Administration > Firmware
# Verify WAN addressing and default gateway
Network > Interfaces > PortB
# Confirm DNS resolution works from the firewall itself
Diagnostics > Tools > DNS lookup
# Check the backup job actually ran
Backup and firmware > Backup & restore
  • Confirm the firmware version and apply any pending update during the window, not after go-live.
  • Check the backup email arrives - an SMTP misconfiguration is invisible until the day you need a restore.
  • Create named admin accounts for each administrator instead of sharing admin, and enable two-factor authentication where available.
  • Set DNS and NTP. Logs with wrong timestamps and blocked lookups are the two most common complaints in the first week.
  • Review the default firewall rules and NAT policies the wizard created. Enable only the network protection features you can actually monitor - turning on everything on a small box costs throughput.
  • Confirm the GuestAP and any unused interfaces are removed on virtual deployments.
  • Decide on logging - local, syslog, or both - and point it at somewhere you will actually look.

Common problems and fixes

  • The browser will not load 172.16.16.16. The web UI listens on HTTPS port 4444, and the default certificate is self-signed, so the browser shows a warning you must accept. Also confirm you are on a machine in the 172.16.16.0/24 network.
  • Setup hangs at "internet required". PortB is in DHCP mode and your upstream is not handing out an address, or DNS is not resolving. Verify the WAN link from the console before retrying the wizard.
  • The firewall rebooted and the management IP changed. If PortA was still configured for DHCP when the wizard finished, it may have taken a lease. Reconnect on the console and set it statically.
  • Registration fails behind a proxy. SFOS needs outbound access for licensing; an intercepted TLS session or a filtering proxy will break it.
  • You cannot reach the internet from the LAN. Usually the default gateway on the LAN interface is missing, or the LAN is not the network you actually configured. Compare the LAN interface address with the clients' default gateway.
  • Backups are emailed but cannot be restored. The master key or backup password is wrong or lost, and there is no recovery path.

Verifying the install

Before you call it done, prove the four things that matter: the firewall is managing on the address you planned, the WAN is up with the expected address and gateway, the LAN hosts can reach the internet through it, and a configuration backup exists that you have successfully opened. Only the last one requires a deliberate test - and it is the one that people skip.

If you want to remove the default GuestAP interface, my blog post Sophos Firewall Remove GuestAP Interface, goes into detail on the process.

If you need more than the 3 initial interfaces, my blog post, Sophos Firewall Interface Mapping on vSphere, goes into detail on how to add additional interfaces on a virtual SFOS and how to map them.

If you want to read more about the initial SFOS setup, here is the Sophos documentation.