{"id":22345,"date":"2016-03-18T12:00:00","date_gmt":"2016-03-18T11:00:00","guid":{"rendered":"https:\/\/www.avanet.com\/blog\/sophos-utm-elevated-9-4-sandbox-user-group-rules-and-waf-cookies\/"},"modified":"2023-11-02T11:03:53","modified_gmt":"2023-11-02T10:03:53","slug":"sophos-utm-elevated-9-4-sandbox-user-group-rules-and-waf-cookies","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/sophos-utm-elevated-9-4-sandbox-user-group-rules-and-waf-cookies\/","title":{"rendered":"Sophos UTM Elevated 9.4 &#8211; sandbox, user\/group rules and WAF cookies"},"content":{"rendered":"\n<p>The new <strong>firmware version 9.4<\/strong> for the UTM is in the starting blocks. The final has already been released. Even though the new <strong>Sophos Firewall OS<\/strong> (SFOS) operating system was introduced with the XG series, the UTM is far from dead. We can now definitely confirm this to you first hand. We were at the Sophos Roadshow in Zurich last week. Both operating systems are being further developed in parallel, and the UTM roadmap continues at least until 2017. So it doesn&#8217;t look like a quick changing of the guard. Especially since it has to be said that we still recommend the SG-Series and would not consider switching until the <strong>Sophos Firewall OS<\/strong> update coming in summer 2016.<\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>But let&#8217;s take a look at what&#8217;s new in the new <strong>Sophos UTM Elevated 9.4<\/strong> firmware.<\/p>\n<\/blockquote>\n\n<h2 class=\"wp-block-heading\" id=\"h-sophos-utm-elevated-9-4-neuerungen\">Sophos UTM Elevated 9.4 innovations<\/h2>\n\n<h3 class=\"wp-block-heading\" id=\"h-1-sophos-sandstorm\">1. sophos sandstorm<\/h3>\n\n<p>The main innovation comes with the sandboxing solution <strong>Sandstorm<\/strong>, which we already announced in <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-sandstorm-with-sandboxing-against-zero-day-maleware-and-apts\/\">a previous post<\/a>. With 9.4, Sandstorm is now integrated into the system and can be activated after purchasing a license. Corresponding licenses can be ordered immediately in our Sophos store for <a href=\"https:\/\/www.avanet.com\/en\/blog\/end-of-sale-of-the-sg-hardware-and-utm-licences\/\">SG Firewall<\/a> or <a href=\"https:\/\/www.avanet.com\/en\/shop\/sophos-firewall\/\">XG Firewall<\/a>. Just click on your hardware model and select the new Sandstorm license.<\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Sophos Sandstorm is currently only available for UTM 9.4. Owners of an XG firewall, with the <strong>Sophos Firewall OS<\/strong>, will have to wait a little longer. Sophos Sandstorm is also not included in the FullGuard bundle and must be purchased separately.<\/p>\n<\/blockquote>\n\n<p><strong>Update<\/strong>: <em>Sophos Sandstorm is now available for UTM and SFOS and can be purchased either individually or in a bundle<\/em>.<\/p>\n\n<h4 class=\"wp-block-heading\" id=\"h-was-genau-macht-sophos-sandstorm\">What exactly does Sophos Sandstorm do?<\/h4>\n\n<p>Sophos Sandstorm complements Sophos&#8217;s existing security products and provides additional protection against advanced persistent threats (APT) and zero-day malware. All files that are downloaded, whether on the web or via Mail Protection are handled as follows.<\/p>\n\n<ol class=\"wp-block-list\">\n<li>The firewall generates a hash value of the file and checks whether it has already been examined. If the file has already been checked, it is already determined whether it should be allowed or blocked.<\/li>\n\n\n\n<li>If the file is unknown, it is transferred to Sophos Labs and analyzed. After the analysis, a report is created for this file, showing exactly what the file tried to do. Finally, the file is deleted from the Sophos servers again.<\/li>\n<\/ol>\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-1024x512.jpg\" alt=\"Sophos Sandstorm - How it works\" class=\"wp-image-12972\" srcset=\"https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-1024x512.jpg 1024w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-64x32.jpg 64w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-300x150.jpg 300w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-600x300.jpg 600w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-768x384.jpg 768w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-1536x768.jpg 1536w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works-18x9.jpg 18w, https:\/\/www.avanet.com\/assets\/news-post-content-sophos-sandstorm-how-it-works.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<h4 class=\"wp-block-heading\" id=\"was-muss-ich-mir-unter-einer-sandbox-vorstellen\">What do I have to imagine by a &#8220;sandbox&#8221;?<\/h4>\n\n<ul class=\"wp-block-list\">\n<li>Secluded, isolated environment in which (unknown) files are executed.  <em>Of course, known malware is blocked right away, so it does not need to be scanned first. But, for example, a new randsomware that downloads and executes code in the background is detected using this technique.<\/em><\/li>\n\n\n\n<li>Site for behavior-based dynamic maleware analysis.  <em>Each file is executed and analyzed, what this does. After that, a report is created and an evaluation is sent.<\/em><\/li>\n\n\n\n<li>Emulated analysis environment for Windows, Mac and Android<\/li>\n\n\n\n<li>Executable files such as (32 or 64-bit), DLLs, Office documents and other file extensions (DF, HWP, XPF, CHM, JAR, APK Archives (ZIP, BZIP, GZIP, RAR, TAR, LHA \/ LZH, XZ)<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"2-benutzer-gruppenbasiertes-regelwerk\">2. user\/group based ruleset<\/h3>\n\n<p>There are now also new configuration options to define <strong>user or group based rules<\/strong>. Until now, it was only possible to assign a fixed IP address to a device via DHCP or directly in the system and then create firewall rules with this object. However, this had the disadvantage that computers that were not assigned to a fixed employee always had the same rule. The <strong>Sophos Transparent Authentication Suite (STAS)<\/strong>, which is familiar from the XG, is now also available for the UTM. This makes it possible to create transparent authentication for firewall and application rules with Microsoft Active Directory.<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"3-waf-persistent-session-cookies\">3. WAF Persistent Session Cookies<\/h3>\n\n<p>Improves collaboration with web applications and web server farms.<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"4-ipv6-ssl-vpn-support\">4. IPv6 SSL VPN Support<\/h3>\n\n<p>Adds the often requested support for IPv6 VPN.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"alle-neuerungen-im-video\">All innovations in the video<\/h2>\n\n<figure class=\"wp-block-embed is-type-video is-provider-vimeo wp-block-embed-vimeo wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"UTM Elevated 9.4 Overview\" src=\"https:\/\/player.vimeo.com\/video\/155150268?h=7694ed899b&amp;dnt=1&amp;app_id=122963\" width=\"1290\" height=\"726\" frameborder=\"0\" allow=\"autoplay; fullscreen; picture-in-picture\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"wann-ist-nun-der-finale-release-der-version-9-4\">When is the final release of version 9.4?<\/h2>\n\n<p>The first UTMs will receive the update in March. It will then be available to everyone by April at the latest. If you can&#8217;t wait any longer and want to install version 9.4 right now, please feel free to contact us.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The new firmware version 9.4 for the UTM is in the starting blocks. The final has already been released. Even though the new Sophos Firewall OS (SFOS) operating system was introduced with the XG series, the UTM is far from dead. We can now definitely confirm this to you first hand. We were at the [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":21227,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[277],"tags":[],"class_list":["post-22345","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/22345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=22345"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/22345\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/21227"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=22345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=22345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=22345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}