Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Bridge Mode in Multi Vlan Enviroment

Need help Sophos XG Bridge Mode in Multi Vlan Enviroment

I am attempting to setup XG in bridge mode on a multi VLAN line between switch infrastructure and the main routing equipment (The trunk from the switches to the router). Based on the documentation, XG claims that this will be handled automatically. However this does not appear to be the case as regardless of what is attempted there is no connectivity on any of the vlans involved (Can not reach VLAN gateway such as 10.0.50.1 for the 50 vlan), but the devices can still reach the Sophos XG Device.

Are there additional setup steps that I have missed during my deployment that are needed to make XG work as desired? I do notice that there have been issues with this kind of setup in the past, has this since been changed in a more recent release or is this still a limitation of XG (Not being able to handle multiple VLANs in bridge mode). To make things clear, the router is to handle all inter vlan and vlan routing, the sophos device is set to bridge to act as an inline security device.

How did you end up configuring your system?



This thread was automatically locked due to age.
Parents Reply Children
  • Hi  ,

    Thanks for reaching out to Sophos Community.

    Could you also try the below steps I have provided and share with us your results.

    Thank you

    Regards,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi

    Thanks for the link to that article. Incidentally I've ended up doing a fairly similar config to that which is partially working - I'm just trying to troubleshoot if the issues are related to the endpoints that are not fully reachable or due to zones and/or firewall rules.

    Can you confirm what the difference is between assigning a vlan to a bridge directly vs assigning to a port within a bridge group?
    Such as if vlan100 is assigned to Port5 inside VLAB_BR1.

  • Hello  ,

    Thanks for the response and taking the time to update. 

    You need to take note of the following warning before adding another interface to the existing bridge group

    Then after saving, the interface would be added to the existing Bridge group in this example. I added Port4

    If you would assign say a vlan60 to this existing bridge, it will be added to the Hardware with VLAB_BR1.60 , VLANID: 60

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi  

    Apologies I mislead you.

    I understand the process to add ports to an existing bridge. While having noted the warning it is a bit arbitrary.... Perhaps more useful if it said specifically what associated settings maybe lost/changed.

    My query is centred on the difference between assignment of the vlan to a particular port that is already associated with a bridge group. Bit of a nested configuration....

    Br0>port4>vlan3

    Versus 

    Br0>vlan7

    If port itself is tagged inside the bridge group does it tag traffic egressing the that port? Does it strip the tag as it goes from port to bridge?

    What happens to the tags when the bridge itself is tagged? Are all ports inherently tagged ports?

    Can you make an untagged port that is associated with a specific vlan?

    Thanks for your guidance 

  • Hi Just wanted to follow up on these queries. Thanks