Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Management Network Unable to Contact Internet. All other VLANS/Network able to contact internet

Hello Everyone. I have my Sophos XG Virtualized in proxmox on a Dell PowerEdge R430, and it is working beautifully, except that my management network doesn't seem to be able to contact the internet, and I'm not sure why. I believe it's because the devices on the management network are not able to contact the gateway due to the ungodly about of ARP requests to find my management network gateway at 10.43.80.1. I've been spending hours on this and am unable to come to a conclusion on this. To be clear, all devices that I have set up for DHCP on the management Network (native VLAN) are able to get an IP address assigned. I have firewall rules set up to allow all of the networks to contact the internet through the WAN. I have 4 other networks set up, and all of them are able to access their gateway along with the internet. I've checked the settings in my SG 300 switch, and I turned off all security features at the moment, thinking it was the switch. I have also attempted to connect to the Management network port directly, and I received a DHCP address, but I am still unable to ping or contact the gateway at 10.43.80.1. I can ping the 10.43.80.1 gateway from my 10.30.15.1 network but I am unable to ping the 10.43.80.1 gateway when I'm connected to the 10.43.80.1 network. Thank you in advance for anyone who is able to assist me. I'd like my VMS and proxmox to be able to access the internet so I can remotely manage the entire network, as I like to remote into my Windows host that runs my WiFI controller and my PRTG network monitor. Below are screenshots of my firewall rules, Ports set up in Sophos, screenshot of the ARP broadcast packets asking for the 10.43.80.1 gateway, NAT policy, and DHCP server setup. I'm hoping someone is able to help me out. Thank you!

  .



This thread was automatically locked due to age.
Parents
  • Hi,

    you have two networks on the same address range.

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • If you're talking about the different zones, it is not the zones because my 10.43.80.0 network was on the LAN zone at first. I tried making a different zone to see if it would work, and it still is not working, unfortunately.

  • Certainly, have look at the addresses on Port A, Port B Port D and port E.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

    1. I put those addresses as part of the management Network, does Sophos look at each interface as a separate network? I thought the physical interfaces should have their own ip address in my management 10.43.80.0 network. Should I set ports C, D, E, and F to obtain their address over DHCP instead of having them as a static address? Port B automatically negotiates a DHCP address from my ISP. 
  • Hi,

    unless using a bridge each interface is a different network and needs a different address range.

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Thank you Ian, I appreciate it. I was under the impression that you could set an IP address on the physical interfaces in the same network. I didn't realize Sophos treated them as their own networks. 

  • That definitely fixed it. Instead of having the router manage my vlans. I ended up having my layer 2 switch manage my VLANs which is how it should be. Then once I enabled igmp snooping in my switch and I enabled multicast forwarding on the Sophos XG, I'm now able to inter-VLAN communicate/route and my management network has internet now. Thank you!

Reply
  • That definitely fixed it. Instead of having the router manage my vlans. I ended up having my layer 2 switch manage my VLANs which is how it should be. Then once I enabled igmp snooping in my switch and I enabled multicast forwarding on the Sophos XG, I'm now able to inter-VLAN communicate/route and my management network has internet now. Thank you!

Children
No Data