Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Break trunk LACP without losing attached DHCP reservation

Hi all,

I need some help with redoing my firewall setup. It was done a while ago and I’ve made some mistakes that I’d like to correct but want to minimise the amount of work.

Here’s what I have : my firewall is a 6 ports firewall. 2 have been put in LACP and are my base LAN with all my firewall. I actually don’t need and don’t use the LACP so would prefer to break it and use them independently.

If I do so, I lose all my VLAN which would not be too bad if I didn’t lose my DHCP servers that have 10s of static ip registered that I don’t want to lose.

How should I proceed to do that with minimal effort ?

Thanks.



This thread was automatically locked due to age.
Parents
  • You could export the config via Import/Export, giving a XML file. The file can include your Interfaces, VLANs and also DHCP server.

    Then you adjust your config. 
    Then you edit your XML file and re upload it to the firewall.

    See: community.sophos.com/.../sophos-firewall-interface-vlan-migration-via-xml-import-export

    __________________________________________________________________________________________________________________

  • Unfortunately it doesn’t seem to work. With this you have to unbound the ports first and doing so results in losing all DHCP configurations

  • Ok I’ll look into the options available. Trying to export everything seemed to just crash unfortunately 

  • How can an EXPORT crash something on your firewall?

    You sure mean your subsequent import after editing?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • The export itself crash. As to how I wouldn’t know. 

  • I never had a "crash" when exporting from XG/XGS systems. What do you mean exactly?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • The export itself doesn’t go to the end. It never finishes. The process does not finish. 

    not sure I understand your question tbh. 

  • Did you try another browser? or another PC-System for the download?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • That is a much more precise and helpful description as "system crashed when exporting". This sounds like "system is not usable anymore after exporting" or "system hangs", which was not the case.

    So please, try to describe your observations as precise as possible. Thank you.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Sure. Maybe try to apply the same to your question. 

    it is not super useful information to answer « it never crashed for me. »

  • It is likely not crashing, instead it will take ages to export a fully configurated firewall with all XML files. That is the reason, you expierence this kind of "crash".

    But only exporting interfaces, VLANs and DHCP should be fine for your goals. Maybe also including NAT / firewall rules as well. 

    __________________________________________________________________________________________________________________

  • Hello Nabil,

    this is not the polite reaction to someone trying to help you.

    I asked some questions, the purpose is collecting infos if original post did not deliver enough info to find a solution.

    Then I gave you some info from my experience, that I never watched one of many customer Sophos firewalls systems we handle, "crashing" when exporting. If you don't like that info, it's fine, it was for free. Bot don't try to educate me. It's give and take in a forum like this.

    Next step in remote troubleshooting is precise wording. So I tried to find out what you mean exactly. That's all.

    I am with LuCar Toni, I think your system maybe just slow and needs time if your export includes all objects.

    But I am out here, I don't need this.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hello Nabil,

    this is not the polite reaction to someone trying to help you.

    I asked some questions, the purpose is collecting infos if original post did not deliver enough info to find a solution.

    Then I gave you some info from my experience, that I never watched one of many customer Sophos firewalls systems we handle, "crashing" when exporting. If you don't like that info, it's fine, it was for free. Bot don't try to educate me. It's give and take in a forum like this.

    Next step in remote troubleshooting is precise wording. So I tried to find out what you mean exactly. That's all.

    I am with LuCar Toni, I think your system maybe just slow and needs time if your export includes all objects.

    But I am out here, I don't need this.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children
  • I do understand and I do agree. But it was a reaction to your comment that was out of line as well. A polite way is simply to ask for extra info without giving me a lesson on how I should have done better. I gave what I thought was the best description in my opinion. Appreciate that we can both learn something here