← All courses

Training

Sophos XG Firewall Administrator

Sophos XG Firewall Administrator

This course is designed for technical professionals who will be administering Sophos XG Firewall and provides the skills necessary to manage common day-to-today tasks.

Learning Outcome

On completion of this course, trainees will be able to:

  • Explain how XG Firewall help to protect against security threats
  • Perform the initial setup of an XG Firewall and configure the required network settings
  • Configure routing, site-to-site connectivity, remote access and wireless
  • Protect web applications using web server protection
  • Configure firewall rules, policies and user authentication
  • Find information using logs, reports and tools

Prerequisites

The prerequisites for this course that trainees should:

  • Understanding of the workings of Windows’ LDAP
  • Understand SSH with Unix-like systems (Ubuntu in this case)
  • Have practical knowledge of networking, including subnets, routing, VLANs, and VPNs
  • Be familiar with security best practices
  • Have experience configuring network security devices

Lab Requirement

Each student will be required to have access to:

  • 2 x Windows Servers
  • 2 x XG Firewall
  • 1 x Linux Server

Duration

Duration: 3 days (4 days if prerequisites not fully met)

Difficulty : High

Type: Hands-on Lab and Theoretical

Assessment: Periodic lab assessment to ensure optimal learning

Outline

The sequence of order may not be as follows, however, the following topics shall be covered within the span of the training session.

  1. Module 1: XG Firewall Overview (45 mins)
    1. Identify the features of the XG Firewall and how the protect against common
    2. Identify the deployment options available for the XG Firewall
    3. Labs
      1. Register for a Sophos Central evaluation
  2. Module 2: Getting Started with XG Firewall
    1. Describe the deployment modes of the XG Firewall
    2. Configure an XG Firewall using the Initial Setup Wizard
    3. Navigate the WebAdmin and manage objects
    4. Explain what zones are, and list the default system zones
    5. Configure interfaces and gateways
    6. Configure static and policy routing
    7. Manage device access and certificates
    8. List the types of routing supported on the XG Firewall
    9. Labs
      1. Use the Initial Setup Wizard to configure a Sophos XG Firewall
      2. Configure a new Sophos XG Firewall by importing a configuration backup
      3. Navigate the WebAdmin
      4. Configure Zones and Interfaces
      5. Create Static Routes
      6. Create a policy-based route
      7. Create Definitions
      8. Configure DNS Request Routes
      9. Import CA Certificates
      10. Create a Configuration Backup
      11. Restore a configuration backup to an XG Firewall
  3. Module 3: Network Protection
    1. Identify the types of firewall and understand the purpose of each
    2. Create and manage firewall rules
    3. Configure and apply intrusion prevention policies
    4. Configure DoS & spoof protection
    5. Enable Security Heartbeat and apply restrictions in firewall rules
    6. Configure Advanced Threat Protection
    7. Labs
      1. Configure Logging
      2. Create Network Firewall Rules
      3. Install the SSL CA Certificates
      4. Install Sophos Central
      5. Publish Servers Using DNAT
      6. Configure IPS Policies
      7. Enable Advanced Threat Protection
      8. Enable DoS (Denial of Service) and Spoof Protection
      9. Configure Security Heartbeat
  4. Module 4: Web Server Protection (45 mins)
    1. Identify the web server protection features and know what they do
    2. Configure protection policies for a web application
    3. Publish a web service using the web application firewall
    4. Use the preconfigured templates to configure Web Server Protection for common purposes, such as
    5. Exchange
    6. Configure SlowHTTP protection
    7. Labs
    8. Web Application Firewall
    9. Load Balancing with Web Server Protection
    10. Web Server Authentication
  5. Module 5: Site-to-Site Connections (55 mins)
    1. Explain the options available for site-to-site connections
    2. Configure an IPsec site-to-site VPN
    3. Implement IPsec VPN failover
    4. Check and modify route precedence
    5. Configure an SSL site-to-site VPN
    6. Explain the deployment modes for RED
    7. Configure and deploy REDs
    8. Configure RED tunnels between XG Firewalls
    9. Labs
      1. Create an SSL site-to-site VPN
      2. Create a Policy-Based Route for an MPLS Scenario
      3. Create an IPsec site-to-site VPN
      4. Configure IPsec VPN network NAT
      5. Configure IPsec VPN failover
  6. Module 6: Authentication
    1. List the supported authentication sources and enable them for services on the XG Firewall
    2. Explain the types of user on the XG Firewall and know when to use them
    3. Configure NTLM authentication for the web proxy
    4. Configure single sign-on using Synchronized User Identify and STAS
    5. Install Sophos Authentication for Thin Clients (SATC)
    6. Create identity-based policies
    7. Enable and use one-time passwords (OTP)
    8. Labs
      1. Create an Active Directory Authentication Server
      2. Configure Single Sign-On Using STAS
      3. Create User-based policies
      4. Configure One Time Passwords
  7. Module 7: Web Protection and Application Control
    1. Configure Web Protection Policies
    2. Identify the activities that can be used to control web traffic
    3. Create keyword content filters
    4. Configure surfing and traffic quotas
    5. Configure Application Filters
    6. Detect and categorize applications using Synchronized App Control and Cloud Applications
    7. Labs
      1. Create Custom Web Categories and User Activities
      2. Create a Content Filter
      3. Create a Custom Web Policy
      4. Create a Surfing Quota for Guest Users
      5. Create an Application Filter Policy
      6. Categorize Applications using Synchronized Application Control
      7. Detect and Categorize Cloud Applications
  8. Module 8: Email Protection
    1. Explain the differences between the two deployment modes for Email Protection
    2. Configure global settings include relay settings
    3. Configure SMTP policies for MTA mode and legacy mode
    4. Configure policies for client protocols
    5. Create Data Control Lists and use them in policy
    6. Configure encryption using SPX
    7. Manage the quarantine using digests and the User Portal
    8. Labs
      1. Enable and Configure Quarantine Digests
      2. Configure an Email Protection policy
      3. Configure Data Control and SPX Encryption
      4. User Quarantine Management
  9. Module 9: Wireless Protection
    1. Identify the access points available and the differences between them
    2. Explain how access points are deployed and the different security modes
    3. Configure wireless networks
    4. Deploy wireless access points and assign wireless networks
    5. Configure hotspots for wireless networks
  10. Module 10: Remote Access
    1. Configure remote access using SSL VPN
    2. Configure an IPsec remote access VPN with Sophos Connect
    3. Configure Clientless Access via the User Portal
    4. Configure remote access for mobile devices
    5. Labs
      1. Configure an SSL Remote Access VPN
      2. Configure an IPsec Remote Access VPN with Sophos Connect
  11. Module 11: Management, Logging and Reporting
    1. Manage an XG Firewall in Sophos Central
    2. Customize and run reports
    3. Schedule reports
    4. Configure logging
    5. Labs
      1. Run, Customize and Schedule Reports
      2. View Sandstorm Activity
      3. Use SF Loader tools
      4. Connection table
      5. Packet capture
      6. Dropped packet capture
      7. Manage and XG Firewall in Sophos Central

Practical, connected learning

My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.