This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem with aliases on LAN interface

Hello,

i have a problem on a customers site.

The customer switched from Sophos UTM to XG firewall.

In the past the customer ran into the problem that his network got to small. Because of ease they just add 2 additinal adresses on the LAN interface with a /24 netmask.

Now after the switch to XG firewall this construction don't work really good, because some connections are marked with "Invalid TCP state"

The main address/network ist 192.168.40.0 the Sophos has the 192.168.40.252. The other networks/aliases on the interface are 192.168.41.0 and 192.168.42.0.

Ich for example a client from 192.168.42.0 network tries to access a printer in 192.168.40.0 network it dont work because ogf invalid tcp state. Smartphone access to Exchange in the 192.168.40.0 network also don't work.

It would be very difficult for the customer to change the hole network to another netmask. So i searched for a solution.

I found this:

set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.42.0 source_netmask 255.255.255.0 dest_network 192.168.40.0 dest_netmask 255.255.255.0

Does anyone know, if this would solve the problem i have?

Thanks everybody for your help

Greets

Andreas



This thread was automatically locked due to age.
Parents Reply Children
  • You should fix this network setup. It looks really bad. 

    You should migrate to VLAN instead. Alias Interfaces are not a way to build up different subnet clients and routing. 

    __________________________________________________________________________________________________________________

  • Yes we know. We already said this to our customer, but for now the customer cannot or dont want to change the network configuration.

    The problem ist we only manage sophos at the customer, everythingelse is managed by the customer and a third party.

    But thanks for your confirmation, we will talk again to the customer