This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Home Edition Sophos XG Basic WAN Routing Issues

I am seriously getting irritated with the Home Edition Sophos XG lately.

First, enabling WWAN broke the install. As soon as the server booted after enabling, no Ethernet devices would work. Not even a "factory reset" fixed it. I have to completely reinstall just to get networking back.

Now I am constantly having connection issues. Weather.com never works, google.com always works, just about every other website is hit or miss. I never get a Sophos page saying it was blocked. The DNS server on the device doesn't seem to function - so if I setup DHCP to configure 172.16.16.16 as DNS nothing resolves but internet somewhat works on 8.8.8.8 or 1.1.1.1 or the device's DNS.

What is really irritating is websites will work then won't. The router log shows "invalid traffic" without any "zones" being defined. And it masquerade settings or connection timeout isn't the issue since it will work then 5 minutes later it won't.

I have the most basic setup. Lan as default network 172.16.16.16/24 on port 1. Port 2 is another router at 192.168.5.1/24. Basic firewall routing that allows "All" apps and web.. I have also tried none and new ones I made. Bottom line, the connection is very unstable.

I use Sophos because I don't want any legal hassles from people I let use the network downloading off BitTorrent.. but other then that I don't really need such a system.

Been using Sophos XG for at least 3 years, I have configured just about everything there is, red, site2site ssl VPN, remote VPN, etc.. and here I'm not doing any of that.. it is an ultra basic setup and it still doesn't seem to work..

Any ideas?



This thread was automatically locked due to age.
  • 1. "no Ethernet devices would work"
    - witch hardware do you use
    - did you got information at the shell using ifconfig?

    2. "The DNS server on the device doesn't seem to function"
    - show us the output from "ipconfig" at the client
    - check the settings at "administration / device access / Local service ACL"
    - try "nslookup" / "server 172.16.16.16" / "www.heise.de"
    -- check if device is able to do DNS at diagnostics / Name lookup ... or network / DNS / test name lookup
    -- try another DNS-Server for device ...

    3. possible you have MTU problems ...
    - try MTU = 1000 at LAN and/or WAN port (increase step by step if successful )


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • I use Intel server. It has been working for years, same device. QOTOM-Q190G4-S02 https://www.amazon.com/dp/B07WZH89NP/ref=cm_sw_r_cp_apa_glt_fabc_WXJC9045N40617V77D1A

    If it was a device issue, reinstalling wouldn't likely fix anything. Can't really be hardware since, as I said, some sites work while others don't simultaneously.

    2.

    There is no ifconfig for Android or windows.

    I did try another DNS server.. bottom line is the firewall itself refuses to act as the DNS server. Or at least, pages don't resolve. DNS does work under diagnostics.

    3. Never changed the MTU settings before, what changed in the latest updates?

    But no seriously, everything was working, I changed a setting (enabled WWAN to try to setup WWAN failover) and everything broke.. that's pretty important.. was working perfectly, enabled WWAN and it was completely broken. I then formatted the hard drive and completely reinstalled.. that was because a factory reset didn't work..

    If I boot windows or Linux on the device everything works perfect. All connections work perfect just having routing Issues..

  • how do you enable WWAN ?

    ifconfig - i really mean ifconfig ... at the XG device


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • What happens if you disable wwan? On windows it is ipconfig. How is the wwan connected to the XG?

    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Network interfaces, Cellular Lan

  • It is an external device that is active all the time, does the interface show it to be active?

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Umm.. if you read my post, I lost all access to the device and formatted and reinstalled..

    Now maybe there was a command at the terminal I could have typed but the device would lockup shortly after boot right as the web interface was coming online..

  • did you get a screen like this?

    I have read your initial post and from additional information you have provided I would suspect the at the device is faulty and taking your system down at hardware level or the interface is faulty.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • The WWAN is not an issue ATM.. just port 1&2.. Port 1 is lan, port 2 is wan.

    And again, some sites work and others do not..

    Pinging always works from any end.. from LAN to Sophos works.. Sophos to LAN works... from Sophos to 8.8.8.8 works.. from LAN to 8.8.8.8 works..

  • Yet the device works perfectly in any other operating system..

    And computers aren't faulty.. the has to be a component that fails.. power supply, CPU, ram, network interfaces..

    And if the device is faulty, how does it route www.netflix.com to stream a movie while at the exact same time speedtest.net doesn't work? How could that possibly be a hardware failure..?

    If hardware fails it is all or nothing.. so the ping would be sporadic, and so would ALL websites.. hardware failures cannot work or not work based on ip address or TCP port.. that is just not how hardware works..