Getting VLANs to work on a virtual install of Sophos UTM 9 turns out to be a bit of a struggle. My setup is as follows:
ESXi 6 with a NIC configured with 4 port groups that all have a VLAN ID (1620, 1621, 1622, 1623). The Sophos install is virtual and has all of the port groups defined as its interfaces. Switch in use is a cisco SG200-26 with the ports configured as trunk with the respected tagged VLANs (multiple ESXi hosts).
Now configuring the interfaces on Sophos UTM to Ethernet VLAN with the VLAN ID seems logical but doesn't seem to work. Hosts connected to the portgroup can't even ping the Sophos gateway of the interface. Configuring the Sophos interface as just Ethernet does make it work but it seems that VLAN tags are dropped since all host on different VLANs can ping eachother. Which undermines the whole VLAN idea.....
I had a go with pfSense which does seem to support this setup but I would prefer to make this work on Sophos. Am I missing a critical part of setup here or is this just not supported?
I do want to route between some VLANs in the end. So goal is to get a 'router on a stick' setup for Sophos. Any ideas on what might fix this?
Regards
This thread was automatically locked due to age.