Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall Home Edition v20 with Sky ISP - DHCP Issue on WAN interface

Hi.

I am having what seems a very basic issue getting my WAN connection connected to Sophos Home Firewall version 20, I'm hoping someone can help?

I've found various posts regarding this over the years but am still unclear exactly why it's still an issue, and why it's not been resolved, so thought I'd post with as much info as possible to see what I've missed, as I'm sure there must be a fix?

Notes:
This configuration works fine with pfsense and opnsense using Sky ISP, so I would expect this to work with Sophos (or my expectatations of Sophos are too high) Slight smile

1. If I connect the wan interface to my TP-Link modem which is in bridge mode, it will not obtain am IP address from Sky's (ISP) DCHP (note again, this works fine with pfsense and opnsense)

2. If I put the dsl line into my Sky router and let it obtain an IP address, and then instantly move that line into my TP-Link modem attached to the WAN interface of Sophos, it uses the WAN IP and works perfectly for 24 hours, until Sky (ISP) sends a DHCP renewal request / the lease expires, which then fails and the WAN connection drops.

3. If I repeat step 2, I can obtain a new IP and Sophos will work again for another 24 hours.

From what I've read on this so far, it seems to be related to "DHCP Option 61" being required on the WAN interface to obtain the IP.

I've seen older posts suggesting to edit files in the var/chroot-xxx directory, which no longer exists and through all my attempts trying other hardware, I cannot get this to work with Sky ISP / VDSL2, but being one of the countries largest ISP's, I'm adamant on getting it to work.

Has anyone else faced with issue with SKY ISP UK?

Thanks in advance!



This thread was automatically locked due to age.
Parents
  • Hi,

    I suspect the issue is Sky appears to use VLAN 10 for its device access? What type of connection are you usingPPPoE or IPoE? Finding the settings is a bit of a challenge.

    Iam

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for the response. Sky use VLAN 101 which I've set at the modem which is in bridge and connects to the ISP (this config works fine with pfsense and opnsense, both obtain a WAN IP via DHCP. Sophos should then get the WAN IP via DHCP, which is the part that fails.

    I may be way off as unsure on the exact cause, but potentially related to the client indentifier, which loops back to the "DHCP Option 61" settings I've seen mentioned in older posts, so it doesn't look like I'm alone, I just can't find anyhting on how people got this working on more current versions.

    Source:
    datatracker.ietf.org/.../rfc2132

    Is there anyone out there who are using Sky ISP with Sophos without any issues I'm wondering?

    I've also seen the following link, but surely it's not only compatable with IDNet?
    https://support.sophos.com/support/s/article/KB-000038812?language=en_US

    As I can get Sophos working for 24 hours with my "workaround", I'm sure it's just something to do with the DHCP on the WAN interface causing the issue, but stuck on where to look next.

Reply
  • Thanks for the response. Sky use VLAN 101 which I've set at the modem which is in bridge and connects to the ISP (this config works fine with pfsense and opnsense, both obtain a WAN IP via DHCP. Sophos should then get the WAN IP via DHCP, which is the part that fails.

    I may be way off as unsure on the exact cause, but potentially related to the client indentifier, which loops back to the "DHCP Option 61" settings I've seen mentioned in older posts, so it doesn't look like I'm alone, I just can't find anyhting on how people got this working on more current versions.

    Source:
    datatracker.ietf.org/.../rfc2132

    Is there anyone out there who are using Sky ISP with Sophos without any issues I'm wondering?

    I've also seen the following link, but surely it's not only compatable with IDNet?
    https://support.sophos.com/support/s/article/KB-000038812?language=en_US

    As I can get Sophos working for 24 hours with my "workaround", I'm sure it's just something to do with the DHCP on the WAN interface causing the issue, but stuck on where to look next.

Children
No Data