This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No wrath like a pre-teen gamer scorned

Hey guys back again with my newbie issues. So I have the UTM up and running without issues and every device in the entire house is connected either wired through a switch or wireless over an AP and happily running traffic through the UTM. All except one... My 12 year old brother-in-laws PS4.  This young man does nothing but play online when he gets home from school so when I told him he might be out of commission for a couple hours while I setup the 'internet' he was a little miffed but didn't complain much. When the two hours were up and I was still not finished he took to following me back and forth from ps4 to WebAdmin and making occasional comments like, "Maybe you shouldn't try doing things you don't really know how to do." After four hours his mental state had degraded significantly. If I can't get this figured out I may have to commit the poor guy.

Here is what I have tried:

I have the UTM acting as a DHCP server and all the other wireless devices are getting leases through the AP and working fine. I have given the Playstation a static IP assignment and defined it as a host. I have created a firewall rule for the PS4 network definition that is PS4->Any->Any. Setup Application Control to allow Playstation Network for the PS4. Turned off IPS and ATP, created an exception in Country Blocking for the PS4. Turned off Web Filtering. ICMP is allowed through the gateway from the internal network.

Thing is I can't find any trace of the PS4's IP in the firewall or Application Control logs(again, IPS and APT are disabled). It doesn't appear that the PS4 is even attempting to get through(I know this is probably false). I have tried a wired connection to the switch as well, same deal.

The PS4 gets an IP no problem but the instant it gets to the test connection step it fails immediately. Shouldn't be a port issue, the any rule should take care of that(it is enabled). I am going to try to contact Sony to find out what exactly takes place during the test but I doubt it will get me anything(besides one more grey hair). I would assume it just pings the Playstation Network server which should be fine. I need a tool like wireshark for the PS4 to get a look into the issue better but I don't think one exists.

I have tried manually inputting the settings on the PS4 and letting it auto assign and both yielded the same issue. It shows the correct static IP, the correct ISP DNS1 and DNS2(getting these from the DNS forwarder in the UTM) but has 0.0.0.0 as default gateway and Failed as NAT Type. 

Any help greatly appreciated!



This thread was automatically locked due to age.
  • Perhaps you would be doing his future wife a favor by leaving it broken...   But to your question:

    Others have posted that it is critical that a static IP be configured outside of any DHCP scope configured on UTM.

    I was confused by the comment that it "gets an IP" during testing.   Is there any chance that it is still asking for a DHCP address and therefore getting something different than the standard one you intended it to use?

    You could get these symptoms if the any of the manually-configured subnet mask, DNS servers, or default gateway settings are incorrect.

    Suggest switching back to DHCP (which should ensure that the settings are usable), then determine the settings that it is using for the moment.   Assign your exceptions until it is working.   A good way to do this would be to create a HOST object (if you con't have one already) and link it to the DHCP-assigned IP address, and assign the exceptions to that object.

    Once you have it working with that address, change the IP address of the host object back to the static one, and reconfigure the machine to the static address, being careful to configure the DNS, Gateway, and Subnet mask correctly at the same time.

  • Haha! Yes I think you may be right about that one!

     

    Ok this is good stuff I will try these suggestions when I get home from work and see what I can figure out. I will get back with you.

    Thanks for your time sir!

  • I marked as the right answer because going back to DHCP led me to finding the issue. I set the default gateway in Network Services ->DHCP->Server to the external gateway instead of setting it to the internal. Setting it to Internal brought the PS4 online.

    My confusion is why the other devices were able to get out to the internet with the original setting but not the PS4.

  • Good question.  One possibility comes to mind.  You have UTM configured with proxyarp enabled.   This allows UTM to reply with it's own MAC when asked for the MAC address associated with the ISP IP address.  Other devices accept the proxyarp but PS4 does not try to use a router outside its subnet, so it never gets the proxyarp response.

  • Ah ok this would make sense as I did not freshly install UTM, this is a box with UTM already on it that was given to me by work to learn on at home. I went through and made changes to all the settings to tailor it to my network needs. Definitely all this troubleshooting during setup has given me a good feel for the interface and where to find everything.

    Do you know how to check for this being enabled? Looks like it is enabled through the CLI i'm sure it is probably checked there as well.

  • You want 'Edit Interface' 'Advanced' in WebAdmin.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • OK thanks for all the help DouglasFoster and thank you BAlfson, you guys are rockstars on here, thank you for all you do!