<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/123392/xg-550-v18-0-1-mr-1-build396</link><description>Hello Sophos Community, 
 i am experiencing the following problem: 
 I am trying to configure the firewall in a way that it forwards a lot of requests unfiltered to two CMTS devices unfiltered via static routing. 
 The CMTS devices are directly connected</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449531?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 09:03:45 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:21bc4716-1fc3-479d-b3f4-8cf3eb00f575</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;My guess is, the Bridge is not correct. Traffic is not routed correctly to the endpoints. A bridge has own Zones for each interface. Did you check, you zones are matching?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449511?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 07:25:02 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:247c5204-8279-4e4f-9bef-75d4d1c34112</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Alexander,&lt;/p&gt;
&lt;p&gt;I am little confused with your setup. CMTS provides a termination for a mobile calls and then sends traffic into the internet either Tunnel or direct connections, correct?&lt;br /&gt;so what traffic will be incoming to the CMTS from the internet, ports, sources etc?&lt;/p&gt;
&lt;p&gt;you advised the CMTS devices are failover and internet access for home users but that traffic would all be sent to the 8nternet with the CMTS as the source not destination.&lt;/p&gt;
&lt;p&gt;ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449509?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 06:50:38 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a20279ea-9b6e-4969-8d54-acbf3ebe7cb3</guid><dc:creator>Alexander Vogel</dc:creator><description>&lt;p&gt;Hi Ian,&lt;/p&gt;
&lt;p&gt;there are two&amp;nbsp; WAN links.&lt;/p&gt;
&lt;p&gt;Also the CMTS devices handle the web traffic of several hundred home internet connections as this is the setup of a small internet provider. The CMTS device basically act as the standart gateway for all the customers routers. A WAF rule i think would only handle HTTP or HTTPS traffic. Since the CMTS devices neet to know the actual destination adress of the packages routed to them i also don&amp;acute;t think a NAT rule would be helpful.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449507?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 06:37:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:899118a9-8854-41f5-b7dc-1b0b6266d548</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Alexander,&lt;/p&gt;
&lt;p&gt;if there is only one source eg one WAN link you do not need routing but either a WAF rule or you existing rule with a NAT.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449506?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 06:35:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:78affb5f-ea2a-4293-886d-40569a65042a</guid><dc:creator>Alexander Vogel</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;the devices are for external use only.&lt;/p&gt;
&lt;p&gt;The devices are also configured to process traffic with any of the destination IP&amp;acute;s that are suppsed to get routed to them. Hence i believe no nat rule should be necessary.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 v18.0.1 MR-1-Build396</title><link>https://community.sophos.com/thread/449505?ContentTypeID=1</link><pubDate>Tue, 13 Oct 2020 06:27:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:67202ec4-5777-4caa-a6f9-d75140bcb65d</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;are these devices for use internally only or are there external users?&lt;/p&gt;
&lt;p&gt;Further you do not appear to a have nat rule.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>