<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Disabling of Management Port</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/135468/disabling-of-management-port</link><description>Hello, 
 I have some issues with the management port which is in the same network as a management network that I want to &amp;quot;hide&amp;quot; behind the firewall. 
 
 I changed some routing (on 10 GBit Port) with resulted into two interfaces on the firewall in the</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Disabling of Management Port</title><link>https://community.sophos.com/thread/500827?ContentTypeID=1</link><pubDate>Tue, 19 Jul 2022 09:43:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7ae57708-cc87-4a02-b5e8-c6b92ad71368</guid><dc:creator>BeEf</dc:creator><description>&lt;p&gt;Hello &lt;a href="/members/lucar-toni"&gt;LuCar Toni&lt;/a&gt;First I had an ip on the management interface configured in the management network that was routed on a&amp;nbsp; switch on each node of the cluster.&lt;br /&gt;&lt;br /&gt;Now we want to route the management network on the firewall itself as a VLAN on an 10 GBit/s interface in order to be able to &amp;quot;hide&amp;quot; it and being able to control the access to the firewall on the firewall.&lt;/p&gt;
&lt;p&gt;For me it looks like the firewall&amp;nbsp;uses&amp;nbsp;the 1 GBit MGMT Network even if disconnect the cable. Only changing the IP to another network helps. However I do not really want to create a separate network for firewall managment.&lt;br /&gt;&lt;br /&gt;Another obstacle seems to be that after we changed the routing it seems not to be possible to access the passive firewall of the management interface of the cluster once we changed the routing to the firewall. This was monitored before because a few updates back we had issues with freezing of hardware (in this case it was no longer reachable on the management interface).&lt;br /&gt;&lt;br /&gt;To be honest I don&amp;#39;t like bridging and I guess it wont solve our problem.&lt;/p&gt;
&lt;p&gt;To make this a little bit more clear:&lt;br /&gt;&lt;br /&gt;Mangement Interface of 1st firewall 172.21.12.81.&amp;nbsp;&lt;br /&gt;Management Inteface of 2nd firewall 172.21.12.82.&lt;/p&gt;
&lt;p&gt;10 GBit/s Interface (actually 2*10 GBit/s LAG)&lt;br /&gt;Subnet mask 255.255.255.0&lt;br /&gt;Zone MGMT&lt;br /&gt;Gateway on 10 GBit/s 172.21.12.5&amp;nbsp; &amp;nbsp; &amp;nbsp;(used by all devices in the management network (vmware server, iLO/iDRAC boards, SAN management, ...)&lt;br /&gt;&lt;br /&gt;(This seems also lead to asynchronous routing which seemst not to be visible on the firewall itself. I was not able to see dropped packets or anything in the log however the communication seems to go from external network - 172.221.12.81 (management interface comes first) - device in 172.21.12.0/24 - which sends the answer throught it&amp;#39;s default gateway.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br /&gt;BeEf&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Disabling of Management Port</title><link>https://community.sophos.com/thread/500759?ContentTypeID=1</link><pubDate>Mon, 18 Jul 2022 18:12:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ea78f48b-1e2c-4108-856c-5322436315e9</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;What is your goal in the End? You could potentiell work with a Network Bridge, if you want to have the same IP/Subnet on the Management Ports.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>