Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I want to assign physical ports of XGS136 to the same segment.

hello.
Sorry for my poor English.

 I was thinking of connecting LAN cables to multiple ports of the XGS136 to create one LAN like a regular router.

ex)

port1=WAN

port2~port10=192.168.10.1~192.168.10.255

Assign default gateway 192.168.10.1 to port 2, and devices connected through port 2 can now connect to the Internet.
However, ports 3-10 cannot connect to the Internet. How can I assign multiple ports to the same segment?



This thread was automatically locked due to age.
  • Hi,

    you create a bridge using the selected ports. You will need to create rules allow traffic flow.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • It is in terms of network setups always a bad idea to build a network with the same network segments on multiple interfaces. 
    The right call is like he explained to build a Bridge instead. a bridge builds a logical interface with multiple interfaces instead. So you have only one interface (the bridge) but could span it across multiple interfaces. 
    That is actually what all cheap router do all the time. The good part is, you dont have to configure multiple DHCP etc. You build it one time for the entire bridge and are done in no time. 

    __________________________________________________________________________________________________________________

  • Thank you, everyone.
    I was able to combine multiple interfaces into one bridge.
    I still can't access the internet.
    How do I allow traffic to flow?
    I've been trying various things, but I can't seem to get it to work.

  • To allow traffic from your LAN to the internet you need a MASQerading rule to masquerade your private IP's behind your public IP-address and you will need a firewall rule to allow traffic from your LAN to WAN.

    Can you show us your interface configuration of the bridge, the firewall rule that should allow traffic to WAN and the NAT rule that MASQs all traffic.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Thank you.

    I've searched and tried various things, but I haven't been able to find the correct answer.
    This is the setup now. Please tell me what is wrong.
    Thank you for your support.

  • See if your mainnetwork (bridge) can also be placed into the LAN zone. Not sure if it is possible since I haven't used bridge for quite some time. It now shows as N/A and therefore maybe it is the reason the firewall does not apply.

    Also I think you also need a firewall Source Zone: LAN, Dest. Zone: LAN, service: ANY, ALLOW to allow traffic between all your bridge ports.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • You seems to have a problem with your license. 

    Check your Administration / Licensing screen. Is there everything in place? 

    __________________________________________________________________________________________________________________

  • Thank you for your advice.
    I don't understand why the bridge is N/A. There doesn't seem to be anywhere to configure it.
    I was messing around with it and couldn't access it anymore, so I'll try resetting it.
    I think the license is valid until 2026.

  • I was able to reset it and connect to the internet. thank you.
    In the end, I was able to connect by creating a LAN to LAN rule in the Traffic to Internal Zone.
    This is my first time using Sophos, so there are a lot of things I don't understand, but I will continue to learn more.
    Thank you very much!

  • Where is your uplink interface?

    Which port do you use as "WAN" port?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.