Guys i had a problem when my UBNT AP AC PRO installed in my network.
FYI :
1. i used XG450
2. topology : sophos -> switch manageable -> LAN (UBNT)
3. no dhcp
4. my AP already connected and get ip
5. im using captive portal for every person when they wanna connect to internet
the problem is AP cannot adopt it, because as i know, it must login via captive portal
already try mac host and added it firewall, but i dont know how to setup the firewall rules
Hi Mate,
Good day!
Make sure that the firewall rule you have created is on the TOP to bypass the Captive portal rules. Dragging it going up to move the rules.
Warm Regards,
Deo Angelo P. Lim | Technical Manager - Philippines
Sophos Certified Architect | Sophos Certified Sales Consultant | Cyberoam Certified Network Security Professional
ARMLINK COMPUTER CENTER
M +63 917 720 2755
Skype: deoangelo.lim
Hay Deo,
Good day too..
i'd already put it on top of the list....
FYI : i created as like this, source LAN source network Bypass_MAC, destination any destination network any, accept.
Do i missed something ?
Hi,
Good day!
It should be working fine. May you provide a screenshot of the firewall rule.
Warm Regards,
Deo Angelo P. Lim | Technical Manager - Philippines
Sophos Certified Architect | Sophos Certified Sales Consultant | Cyberoam Certified Network Security Professional
ARMLINK COMPUTER CENTER
M +63 917 720 2755
Skype: deoangelo.lim
Hi,
Good day!
Its seems to be correct. For further checking add me on Skype Pal.
Regards,
Deo Angelo P. Lim | Technical Manager - Philippines
Sophos Certified Architect | Sophos Certified Sales Consultant | Cyberoam Certified Network Security Professional
ARMLINK COMPUTER CENTER
M +63 917 720 2755
Skype: deoangelo.lim
Hi Ricky ,
You may need to check if the request incomming to XG is of the same Mac address or differnet.
Test
You may use the TEST IP 1.2.3.4
Open Disgnostics on Sophos XG and enter the BPF string host 1.2.3.4
Go to the system or test machine and enter the same on the browser. You should see the MAC address of the incomming packet. If it is different you may need to check if there is any 3rd Party Router wireless point added . If So configure it as a Access Point so the MAC address will not be changed. Otherwise any Layer 3 device could change the Mac address even though NAT is not applied.
Regards,
Aditya Patel
Global Escalation Support Engineer | Sophos Technical Support
Knowledge Base | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'This helped me' link.
hy adit,
ok sir im gonna check it..
but can u share how to setup the rules for firewall ?
i think im still confuse about the right rules
thanks before