This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How complicated is it to connect 2 ISP 2 firewalls together?

I have 2 firewall (SG125, SG135) and 2 ISP (ISP U and ISP T).

SG125 connects with ISP T and have 2 VLANs 192.168.40.0 and 192.168.41.0.

SG135 connects with ISP U and have 1 VLAN 192.168.1.0.

 

Is it possible, that I connect a LAN cable between SG125, SG135 and utilize both ISP either be it load balance or failover?

If possible, how should I start? 



This thread was automatically locked due to age.
  • Hi Esmonde and welcome to the UTM Community!

    Are these two SGs in the same building or room or can they somehow be connected directly?  What Sophos subscriptions are on each?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

     

    The 2 devices are in the same building within blocks away and there is only 1 network cable available for me to connect the 2 SGs together.

     

    Sophos subscription is base functionality, network protection, web protection and sandstorm. 

     

    Regards,

    Esmonde

  • Then, yes, it's possible.  The configuration in both will be nearly identical.  You will need to learn about Uplink Balancing and Multipath rules.  You will need firewall rules, masquerading rules and changes to 'Allowed Networks' in Web Filtering to enable the subnet(s) connected to the other SG to use the remote SG.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    please keep in mind, if the connection cable between both UTM's is copper and longer than 100m you'll run into problems.

  • Dear Bob,

    That's very complicated to a beginner to firewall like me. 

    Is there any documents available?

    I tried to find but no luck with keywords. 

     

    Regards,
    Esmonde

  • If this is a business, I would recommend that the initial configuration be done by someone in your area that has a lot of experience.  Once configured properly, the UTM is a dream to administer.  Configured by an experienced, talented CCIE with no WebAdmin experience, it's a nightmare.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA