Step 1: Log into Sophos XG Firewall

– Open a browser and enter the IP address of your Sophos XG Firewall. – Enter your admin credentials (username and password).

Set up Web Filtering

Go to the “Web” Section: On the dashboard, click on "Web" in the left menu. – Enable Web Filtering:In the "Web Protection" section, click on "Web Filtering". Click on "Enable" to activate web filtering.

Configure the Web Filtering Policy:

– Under the "Policies" section, create a new "Policy" or modify an existing one. – Click "Add Policy" or select an existing policy to edit.

Choose Filtering Criteria

Under the policy settings, you can set the filtering options: – URL Filtering: Block or allow specific URLs. – Category-based Filtering: Use predefined categories like social media, gambling, adult content, etc., and block/allow them. – User/Group-based Filtering: If you use Active Directory (AD), you can configure filtering policies for different user groups.

Configure SSL Inspection

Go to SSL/TLS Inspection: – In the "Web" section, click "SSL/TLS Inspection". – Enable SSL inspection to inspect encrypted web traffic.

Configure the SSL Certificate: – Download the Sophos SSL certificate from the firewall and install it on client devices to prevent SSL errors.

– Choose between "Deep Packet Inspection" or "Certificate Inspection". – Save Changes.

Configure Web Application Firewall (WAF) Go to Web Application  Firewall: – Under "Protect", select "Web Application Firewall".

Configure WAF: – Save Changes.

– Add a new "WAF Rule". – Choose the type of protection (e.g., OWASP top 10, custom rules). – Define the backend web server and port.

Enable and Test the WAF  Rule. – Ensure the rule is working by testing it against your web application.

Set up Logging & Alert

– – Go to Logging & Reporting:In the main dashboard, click on "Logs & Reports". – Configure Logging:

– Enable logging for web traffic, URL filtering, SSL inspection, etc. – Set up alerts for suspicious web traffic or policy violations.

Apply the Web Filter Policy to Users or Network

Apply the Policy to Network Zones or Users: – Go to "Policy" and select the network zone (e.g., LAN, WLAN) or specific users/groups to apply the policy.

Save the Policy and ensure it’s active.