Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connection between two different subnets

Hi community,

I'm trying to connect two different Subnets. This is the environment:

Subnet A
192.168.1.0 /24
Gateway: 192.168.1.1
Port 4: Company with DHCP address 192.168.1.55
Device: FritzBox

Subnet B
10.0.100.0 /24
Gateway 10.0.100.1
Port 1: LAN
Device Sophos XGS87

I would like to use a printer (192.168.1.100) from the LAN of the Sophos XGS, but there is not connection possible and I don't know why. I configured a firewall rule:

DEST: LAN & Company
SRC: LAN & Company
ANY ANY

What is my fault? Do I have to configure a static routing or anything else?

I would be very thankful for your help.



This thread was automatically locked due to age.
Parents
  • Are both network at the same location?

    You might remove FritzBox as gateway and create another interface on Sophos. But… your Setup is unclear.

    Can you draw a network diagram explaining your setup?

    Is it WAN->FritzBox->Sophos? Or WAN1->Sophos and WAN2->Fritzbox? How are they related to each other?

  • Yes both networks are at the same location. This is the setup, I hope this is helpful.

  • Okay, two options:

    1. Add route on FritzBox: 10.0.100.0/24 at 192.168.1.55 but might still be a problem because packet takes not same way to and from target.

    2. i‘d suggest adding fritzbox as second wan, so you will have high-availability wan using sd-wan as well. Sophos will be gateway for both networks:

  • The second network (fritzbox) belongs to another company, we could not use this connection for ha wan. I only want to use the printer because the printer is the only ressource that should be shared for both networks. 

  • you might create s-nat rule, to masq traffic. That would skip fritzbox as gateway for 192.168.1.0/24 Clients.

    from 10.0.100.0/24 to 192.168.1.0/24 change source to Port 4 Address 192.168.1.55/32.
    Due to this printer will not see 10.0.100.0/24 network. Source will be 192.168.1.55 and send packets back to 192.168.1.55.

Reply
  • you might create s-nat rule, to masq traffic. That would skip fritzbox as gateway for 192.168.1.0/24 Clients.

    from 10.0.100.0/24 to 192.168.1.0/24 change source to Port 4 Address 192.168.1.55/32.
    Due to this printer will not see 10.0.100.0/24 network. Source will be 192.168.1.55 and send packets back to 192.168.1.55.

Children