Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Ports not passing internet

Hello,

Thank you in advance for your assistance and patience!

I am running Sophos XG Software version on an Dell Optiplex 3020, with an intel quad port NIC. I have Port 4 set up as the WAN, and Port 1 set up as the LAN, and am able to connect to the internet successfully.

However, I am unable to get Port 2 or Port 3 to connect to the internet - I have them configured as Network Zone: LAN, and DHCP and Static IPs respectively. When I connect an ethernet cable the Configure: Network page displays that the interface is Connected with 1000 Mbps - Full Duplex, but the internet is not accessible using the port. Furthermore, the port configured to use DHCP does not display an address, nor does the connected computer receive an IP address.

I've tried several different configurations (different IP assignment, network zones, etc) but have the same issues with each.

Any thoughts on where I am going wrong? Please let me know if there is more useful information that I can provide.

Thanks and best!

Mike



This thread was automatically locked due to age.
Parents
  • Hi,

    have you created firewall rules to allow the traffic out?

    Please post screenshot of your DHCP server setup.

    Ian

    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I haven't, but I believe that the default rule should be enabling traffic; I may have that mixed up, though! I've attached screenshots of my firewall, interfaces, DHCP server settings, and the apparent inability to create a DHCP server on Port 2, which is connected as in the screen grab.

    Thanks for your help!

    Mike

  • Hi,

    the basic tenent of any good firewall is drop all and you need to create rules to allow traffic out. The default rules created during installation are good to get you going, but I would recommend that you build your own with a finer filtering and try to avoid using ANY in service or Source network.

    Before you can add a DHCP server to an interface you have to assign it an IP address.

    Ian

    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    the basic tenent of any good firewall is drop all and you need to create rules to allow traffic out. The default rules created during installation are good to get you going, but I would recommend that you build your own with a finer filtering and try to avoid using ANY in service or Source network.

    Before you can add a DHCP server to an interface you have to assign it an IP address.

    Ian

    XG115W - v20.0.3 MR-3 - on holiday

    XGS118 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Okay, got it. I misunderstood the DHCP setting - it is for the interface itself, not for whatever is connected to the interface. I set it to static, and was able to set up DHCP and get an internet connection - thanks for your lightning help!

    I do plan to redo the firewall filtering once I got basic connections working; just left the default as placeholders while figuring out the more basic parts of setup setup.

    Thanks again for your help and advice!

    Mike