Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setting up a trunk link to a Layer 2 switch (from a Sophos XGS 136 device)

Hi,

I'm in the process of setting up a basic trunk link for multiple VLANs between a Sophos XGS 136 device and a basic HP 2920 layer 2 switch. The end result is to configure VLAN access ports on the HP layer 2 switch.

I haven't had a lot of experience in setting up firewalls and switches so I admit I may not have the concepts correctly in place.

Do I do the following:

- Configure the VLANs on the Sophos appliance (with unique VLAN ID)s and bind them to a free physical port/interface ? 
- For each VLAN I have the option of creating a DHCP server and a corresponding firewall rule on the VLAN interface ?
- Patch the connection from the physical interface (where the VLANs are defined) to a destination port on the switch. Configure the destination port on the switch as a "trunk" link

E.g.

VLAN 10 is defined to have the range 192.168.10.0/24 with VLAN ID 10
VLAN 20 is defined to have the range 192.168.20.0/24 with VLAN ID 20
VLAN 30 is defined to have the range 192.168.30.0/24 with VLAN ID 30

- If they are all bound to a free physical port (e.g. Port 6) does it matter what the IP address of the physical port is (e.g. 10.10.1.0/24) ?
- If all VLANs have corresponding DHCP services running, which DHCP server takes precedence is one connects a device to the physical port (e.g. Port 6) ?



This thread was automatically locked due to age.
Parents
  • Hi,

    none of the DHCP servers will respond to a physical connection, they will only respond to requests from the appropriately tagged/untagged ports on your switch.

    If you are not connecting any devices on the physical port then you can use a smaller range or no range.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian,

    Best reply so far. In my case the only physical device that is going to be connected to that physical port is the layer 2 switch with the trunk link.

    So in this instance I could set the IP address of the physical port to a /32 address. As far as I can tell I don't have the option of not setting an IP range for the physical port

    As for DHCP server not responding to the physical connection, that is consistent with my understanding. DHCP requests should only respond to tagged ports on the switch corresponding to the configured VLAN on the access port

    I'll see how I go.... 

Reply
  • Hi Ian,

    Best reply so far. In my case the only physical device that is going to be connected to that physical port is the layer 2 switch with the trunk link.

    So in this instance I could set the IP address of the physical port to a /32 address. As far as I can tell I don't have the option of not setting an IP range for the physical port

    As for DHCP server not responding to the physical connection, that is consistent with my understanding. DHCP requests should only respond to tagged ports on the switch corresponding to the configured VLAN on the access port

    I'll see how I go.... 

Children
No Data