Setup
Sophos XG 330:
LAN Port 9 10.0.0.248/24
LAN Port 9.8 10.0.8.248/24
FIREWALL RULE: LAN any - LAN any ALLOW
Port 9 plugged in Switch port 24
Layer3 Switch:
VLAN 0 10.0.0.1/24
VLAN 8 10.0.8.1/24
Port 24 Trunk ALLOW ALL VLAN
Port 1 VLAN=0
Port 2 VLAN=8
PC1:
IP 10.0.0.222/24
Gateway 10.0.0.248 <- Sophos is the Gateway here.
Plug in Switch Port 1
PC2:
IP 10.0.8.222/24
Gateway 10.0.8.1 <- Layer3 Switch is the Gateway here.
Plug in Switch Port 2
In this config, PC1 can ping PC2, but PC2 CAN'T ping PC1
On the log I have : ICMP packets with invalid ICMP type/code.
If I swap both gateway on the PCs to either same it works it doesn't matter which one I choose.
It's when they are mismatch that I have this issue. And for my used case, I need it to be able to be mismatch.
This setup works in my Sophos SG 330... That will be EOL soon...
This thread was automatically locked due to age.