Hi all, i have had a look at the Invalid Traffic page but as stated at the bottom doesnt resolve the issue, just reduces the number of logged entries
My setup is as follows
Core network is TPLink Omada (Manages the vlans)
Sophos setup:
Port1 - Management LAN (VLAN 1)
Port2 - Internet WAN
Port3 - VLAN 131 Subnet LAN (gateway for this is the IP of Sophos) (Management wifi)
Port4 - VLAN 121 Subnet LAN (IOT wifi)
Port5 - VLAN 111 Subnet LAN (userland wifi)
When using VLAN 131 subnet I cannot access any resources on Management LAN (by default this is what I want for my main VLAN 111, but still need my management access).
Ive added internal allow rule to the fw (though bit surprised its going through fw considering each subnet is set to LAN) ... and its allowed me now to ping everything and use nmap to the specific ports successfully on the management LAN, but use a web browser the firewall logs with 'Invalid Traffic' (nmap logs successfully hits the rule and gets passed through no issues
Any ideas?
Please provide a simple network diagram. If the switch is managing the VLANs then you don't need VLANs on the XG because all traffic will be directed to the XG through an untrunked port.
Ian
XGS118 - v21.0.1 MR1
XG115 converted to software licence v21.0.1 MR-1
If a post solves your question please use the 'Verify Answer' button.
Controller, router, switches, and AP's are Omada like I mentioned, VLANs and subnets are defined in that system. These lead to a poroxmox server that attaches 5 virtual nics (with vlan tags on the 131, 121, 111 networks). Of wich only my testing and future management vlan 131 is using the sophos fw IP on the subnet as its gateway