This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't access UTM behind another UTM

Scenario: Our shop has an SG115 with all ports used, Eth0: Office LAN (192.168.0.X), Eth1: External, Eth2: Shop LAN (192.168.10.X), Eth3: Test LAN (192.168.20.X)

We received 5 brand new UTM devices for a customer's sites and are doing some pre-configuration in house before we take them all out. 1 SG210 and 4 SG125's. We have all 5 units behind Test LAN with addresses from 192.168.20.2-6.

The problem is with 192.168.20.3, you can't connect to it from the Office LAN, not pingable, can't get to the GUI but all other devices are reachable and working fine. I've tested it from the Shop LAN and it can see it. I've tested it from an SSLVPN remote connection using 192.168.5.X and it's reachable. 

A computer behind the problem device can open the GUI up no problem, it can also open it up when plugged parallel to the device with a 20 address. I've changed external NICs on the device, I've changed external IPs, rebooted the device along with our main shop device.

I'm at a loss because there's other exact model devices on the same subnet that have no problem with the exact same configuration. Traffic to 192.168.20.3 is not making it through the shop device but no events show up dropped in the firewall log.

Any ideas of attack?



This thread was automatically locked due to age.
  • So is it a firewall rule issue?

     

    also eth3 on a 115 is the HA port, have you configured HA by chance or have some residual configuration left over. HA will bascailly not allow you to use the port for anything but HA and the network attached to HA is not routable. If the adapter has been assigned for HA you need to remove it.

     

    Has a correct gateway been assign on the device u have problems with,

     

    You should eliminate your shop UTM by directly plugging a laptop with the same ip range as the UTM ur having troubles with and directly connecting. If you can directly connect with a laptop its the device having problems, if its not, its ur UTM. Got to go step by step, eliminate any additonal things before connecting it all together.

  • What is configured under Managment -> Webadmin settings -> General under Allowed networks with all of the new devices?

    Is your SG115 allowing traffic on port 4444 from it's Office LAN to it's Test LAN?


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • HA was never configured, I turned it's operation off in Management then configured it as an interface.

    Yes, the gateway information is correct in the device, it communicates with every other device on all networks except shop.

    I've moved a laptop from point to point and everything works, inside and out except when you get to the Shop LAN.

    Webadmin settings is Any network as allowed to connect to the device.

    Update: No changes were made since I posted my question and now 192.168.20.2 has the same issue of not being visible from Shop network with .3 but all other devices work. I think there are gremlins at work.

  • Is the connection between your LAN and the Test-LAN proxied or not? You didn't answer that question yet.

    Gruß / Regards,

    Kevin
    Sophos CE/CA (XG+UTM), Gold Partner

  • You will want to reconfigure access to webadmin from any to just the devices (or subnets) you really want to access webadmin (ie your own internal subnets and/or some VPN users).


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.