Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Wireless not working through SFVH firewall

Hello,

So I'm running SFVH (SFOS 19.5.3 MR-3-Build652). The firewall is running on a VP2410 mini PC. My Asus router is 'bridged' to this unit and everthing works fine with one exception: The WiFi on the Asus is somehow being blocked by my Firewall and I can't access anything on my network. 

My Topology is this: 

Internet-->Router-->Sophos Firewall (VP2410)-->Cisco switch-->all other devices connected to switch via ethernet LAN.

So when I try to used the WiFi on the Asus Router, the VP2410 running Sophos is preventing this from reaching the switch. I know this because when Router is connected directly to switch WiFi and ethernet work fine. However I want the protection of the firewall and hence WiFi is prevented from working.

I've added the Wireless Networks into Sophos by reading the help articles but still can't connect. At this point, I'm guessing on what to try next and I get nervous when I'm guessing as I could break something else and not realize it until later.

The router and VP2410 are 'bridged' and I've set port 2 for WAN and port 3 for LAN. Just not sure what to do next. Any help or guidance would really be appreciated.



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    Are the only two ports you’re using in the Sophos Firewall Port 2 and Port 3? 

    Is the 3rd party router in the WAN zone? If so, you might want to move it to a different port in the Sophos Firewall, either in a LAN or DMZ.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hello EmmoSophos,

    I thought when you are in bridge mode, the output from router had to go into the WAN port 2 of Sophos. So yes, I'm just using ports 2 and 3. By putting into a LAN port, how will that affect the Bridge between router and Sophos? From your suggestion, I'm guessing not much but I can't risk internet going down right now.

    I won't be able to test this until tomorrow as we're actively using internet for work.

  • Hi,

    the router/AP should be on the LAN side of the XG is you want to use the AP function? The XG could connect directly to the internet depending on your WAN connection type.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I moved router to LAN side of XG and I have access to my server now. But by moving to LAN from WAN, isn't the XG (VP2410) now just acting like a switch? In other words, all data incoming from router is just being passed through without XG monitoring the data. Is that assumption correct as that's not what I want but I do need access to server via WiFi at same time?

  • If the server is on the same network as the router and AP then the XG will not see the traffic.

    If the server is on a different network then you will need firewall rules to allow traffic between the LANs and you need to change the router into bridge mode so the firewall will see the original packets.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • If the server is on the same network as the router and AP then the XG will not see the traffic.

    If the server is on a different network then you will need firewall rules to allow traffic between the LANs and you need to change the router into bridge mode so the firewall will see the original packets.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children