Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Bridge Mode in Multi Vlan Enviroment

Need help Sophos XG Bridge Mode in Multi Vlan Enviroment

I am attempting to setup XG in bridge mode on a multi VLAN line between switch infrastructure and the main routing equipment (The trunk from the switches to the router). Based on the documentation, XG claims that this will be handled automatically. However this does not appear to be the case as regardless of what is attempted there is no connectivity on any of the vlans involved (Can not reach VLAN gateway such as 10.0.50.1 for the 50 vlan), but the devices can still reach the Sophos XG Device.

Are there additional setup steps that I have missed during my deployment that are needed to make XG work as desired? I do notice that there have been issues with this kind of setup in the past, has this since been changed in a more recent release or is this still a limitation of XG (Not being able to handle multiple VLANs in bridge mode). To make things clear, the router is to handle all inter vlan and vlan routing, the sophos device is set to bridge to act as an inline security device.

How did you end up configuring your system?



This thread was automatically locked due to age.
Parents
  • Hello Samir,

    Could you share the documentation that you referred to on configuring your setup? If you may also share your network setup/diagram that would be much appreciated.

    Further, could you try this community RR if it would be able to help you on your scenario:  Sophos Firewall: How to Configure Inter-VLAN Routing on Sophos Firewall 

    I was able to configure multiple VLANs on 2 physical interfaces that I bridged on SFv20: 

    Could you share with us the results after you followed the RR above if still does not work, could you also share the results of Log Viewer when you are initiating a traffic? 

    Thanks for your time and patience and thank you for choosing Sophos.

    Regards,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • I believe the question is not about VLAN interfaces on the firewall, since the original poster refers to the router handling the inter-vlan traffic and not the firewall but rather if you have two bridged interfaces on the XG can you pass a vlan through that bridge and onto something else (in this case the router).

    I believe this is the case, though I've not tried it myself (there is a "filter VLAN" option in the bridged interface settings which suggests that's possible).

Reply
  • I believe the question is not about VLAN interfaces on the firewall, since the original poster refers to the router handling the inter-vlan traffic and not the firewall but rather if you have two bridged interfaces on the XG can you pass a vlan through that bridge and onto something else (in this case the router).

    I believe this is the case, though I've not tried it myself (there is a "filter VLAN" option in the bridged interface settings which suggests that's possible).

Children
No Data