Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VLAN clients receives IP from DHCP but can't access internet

Hi! I've created a new VLAN and DHCP server for it on the firewall. The clients on the VLAN can successfully get an IP address from the DHCP server but cannot resolve websites / or have internet access. Any tips? See below DHCP server config & firewall rule:

This thread was automatically locked due to age.
  • please check the value your wifi network is showing to see if it matches your dhcp settings.


    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • So right now I haven't connected any clients from the WIFI network yet, as I want to make sure this works first. So for now I've just dedicated a switch port to the new VLAN and have a wired laptop into it. It gets a proper IP address from the DHCP server, just no internet.

  • Hi dsurfer 

    As per the firewall rule, LAN is the source zone, the same is applied to VLAN.

    If changing to the proper zone doesn't help check packet capture under MONITOR & ANALYZE-->Diagnostics-->Packet Capture Click on configure Enter BPF string host and proto ICMP to verify the firewall rule.

    Also, check DNS on System is getting resolved, and share any error message from the browser in case the internet not working 


    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks, yes, the Zone is confirmed to be LAN on the VLAN interface and the source on the firewall rule. I tried doing a capture packet with the host string and no records come up.

  • Are you connected on Windows ?

    1.Share ipconfig /all 


    3.tracert -d 

    4. From SSH of Sophos XG check 

    console>tcpdump 'host and proto ICMP

    console>dr 'host and proto ICMP

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Yes it's a windows machine that I have testing here:

    I'll do the XG console commands in a few min

Reply Children