<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/105765/routing-to-another-gateway-on-the-same-lan-subnet-as-sophos-xg</link><description>Hello everyone, 
 
 I have a behavior I don&amp;#39;t know how to solve. 
 Your help will be really appreciated :). 
 My Sophos XG is the default gateway, DGXG (192.168.0.250), for my subnet LAN1. My LAN1 is deployed between 2 sites using a fibre. 
 DGXG is connected</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/421131?ContentTypeID=1</link><pubDate>Tue, 19 Nov 2019 18:46:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f8595130-e3ce-4b73-9f28-8897f50c4125</guid><dc:creator>Edson Siqueira</dc:creator><description>&lt;p&gt;Hello&amp;nbsp;ShunzeLee,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;m trying to do the same thing, but I tried to use this command &amp;quot;set advanced-firewall bypass-stateful-firewall-config&amp;quot; and it didn&amp;#39;t worked for me. Actually the command worked but the route didn&amp;#39;t, the machines in the subnet 192.168.0.0 /24 can&amp;#39;t access machines in the subnet 192.168.5.0 /24 for example.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If I add a static route to 192.168.5.0 /24 in&amp;nbsp;any windows machine in the subnet 192.168.0.0 /24 it works good, but if an add a static route in Sophos XG like bellow it didn&amp;#39;t work.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Can you help me?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/126/pastedimage1574188675584v1.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/126/pastedimage1574188675584v1.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386992?ContentTypeID=1</link><pubDate>Fri, 19 Oct 2018 07:58:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a8d6940c-85ed-4a0a-a663-ce1c8870bb55</guid><dc:creator>max.mo</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I can confirm that worked perfectly .&lt;/p&gt;
&lt;p&gt;No need to use a MASQ.&lt;/p&gt;
&lt;p&gt;Thanks again.&lt;/p&gt;
&lt;p&gt;Enjoy your weekend.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best Regards, Maxime&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386972?ContentTypeID=1</link><pubDate>Fri, 19 Oct 2018 03:32:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f7d37a6e-2934-4e5d-99d5-320a542d4c8f</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I hope that works for you, but I would have thought an MASQ on your outgoing gateway is required?&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386971?ContentTypeID=1</link><pubDate>Fri, 19 Oct 2018 03:03:18 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5e5fe019-68d9-4908-aedf-716edf1ec184</guid><dc:creator>max.mo</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks a lot !&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I completed your post with &lt;a href="/products/xg-firewall/f/sophos-xg-firewall-general-discussion/79041/troubleshooting-guide-for-xg"&gt;https://community.sophos.com/products/xg-firewall/f/sophos-xg-firewall-general-discussion/79041/troubleshooting-guide-for-xg&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I think it solved my case.&lt;/p&gt;
&lt;p&gt;I need to do more tests to be sure :)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386965?ContentTypeID=1</link><pubDate>Fri, 19 Oct 2018 01:55:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4eb001fa-256d-45dd-9730-f52b2a27d4bb</guid><dc:creator>ShunzeLee</dc:creator><description>&lt;p&gt;Maybe it was blocked with XG as&amp;nbsp;asymmetric route.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/126/_5E970D5C317AEF8D3175_.png"&gt;&lt;img src="/resized-image/__size/1040x1240/__key/communityserver-discussions-components-files/126/_5E970D5C317AEF8D3175_.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Only one way pass through XG will be blocked as&amp;nbsp;asymmetric route.&lt;/p&gt;
&lt;p&gt;If you can&amp;#39;t change the network structure, you may bypass asymmetric routing on XG with following command.&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff0000;"&gt;set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.0.0 source_netmask 255.255.255.0 dest_network 192.168.X.0 dest_netmask 255.255.255.0&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff0000;"&gt;set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.X.0 source_netmask 255.255.255.0 dest_network 192.168.X.0 dest_netmask 255.255.255.0&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Try it.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386963?ContentTypeID=1</link><pubDate>Fri, 19 Oct 2018 01:29:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:13ad40eb-bf35-4795-89d2-81519a6fe75f</guid><dc:creator>max.mo</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks for your response.&lt;/p&gt;
&lt;p&gt;My rule is on top of the top and there is no blocking traffic :&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/126/pastedimage1539930163029v1.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/126/pastedimage1539930163029v1.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/126/pastedimage1539930185036v2.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/126/pastedimage1539930185036v2.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;There was hit to the rule :&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/126/pastedimage1539930237597v3.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/126/pastedimage1539930237597v3.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;the other gateway device is a sonicwall. WE replaced a sonicwall by one sophos but there is still one sonicwall on the other side.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I will try to sketch it out today.&lt;/p&gt;
&lt;p&gt;Thanks for your help.&lt;/p&gt;
&lt;p&gt;Maxime&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386938?ContentTypeID=1</link><pubDate>Thu, 18 Oct 2018 17:37:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:01ebf046-7dba-453e-9ea2-c0f27e85c858</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;where does your rule sit in the list of rules?&lt;/p&gt;
&lt;p&gt;Please post a copy of your rule.&lt;/p&gt;
&lt;p&gt;Which firewall rule is blocking the traffic?&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386935?ContentTypeID=1</link><pubDate>Thu, 18 Oct 2018 17:06:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:08ce70de-08f9-486b-8a4d-1fb0189bf8f8</guid><dc:creator>AADD</dc:creator><description>&lt;p&gt;Either method mentioned should work, however each gateway or device needs to know the routes on each end.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I did this while migrating to Sophos from Sonicwall.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Maybe I am missing something, can you sketch it out?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/386891?ContentTypeID=1</link><pubDate>Thu, 18 Oct 2018 09:32:19 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b6fcaa13-61e8-4fb3-a430-47c882de2f2f</guid><dc:creator>max.mo</dc:creator><description>&lt;p&gt;Hell I tried to do a firewall rule with a gateway but this did not work either.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Do you have another idea?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks for your help.&lt;/p&gt;
&lt;p&gt;Best Regards, Maxime&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/385790?ContentTypeID=1</link><pubDate>Thu, 11 Oct 2018 04:24:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:661dc7a8-c6fe-4ef6-987b-490c0e629bb4</guid><dc:creator>max.mo</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks for your response.&lt;/p&gt;
&lt;p&gt;I did not try that one.&lt;/p&gt;
&lt;p&gt;I know the destination subnet.&lt;/p&gt;
&lt;p&gt;So you mean changing the primary gateway in the advanced setting of the firewall network rule?&lt;/p&gt;
&lt;p&gt;good idea, I will give it a try tomorrow.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;thanks !&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Routing to another gateway on the same LAN Subnet as Sophos XG</title><link>https://community.sophos.com/thread/385788?ContentTypeID=1</link><pubDate>Thu, 11 Oct 2018 04:16:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:423a4104-7a1b-48f8-b2be-17e00813776f</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Why not remove all your routes and do it with a firewall rule, you must know the destination IP address range?&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>