Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Fixed

Fixed



This thread was automatically locked due to age.
  • Hi Rob,
    I am using XG in Gateway mode and dhcp on wan interface and it is working since beta 2 with no issue. Are you using IPv6 on WAN?
    What the system log says from System> Diagnostics> Log Viewer ?

    Luk
  • Rob,

    Are you deploying the firewall in Bridge Mode? In Gateway mode you don't need the above mentioned rule, try accessing the firewall from LAN zone, I guess there is MAC binding configured upstream

    Navigate to System> Network> Interfaces> PortB:

    Network Zone: WAN
    IP Assignment: DHCP

    Advanced Settings:

    Interface Speed: Auto-Negotiation (Default)
    Override Default MAC Address: Add MAC address of old firewall public interface

    Save.

    Hope that helps.

  • You can't get an IP in gateway mode? Why do you configure a rule related to bridge devices? I'm using Unitymedia (cable provider) and I had also some problems getting an IP address. A reboot solves my issue (wait 15 minutes between router change, sometimes the ISP blocks new Mac addresses for a while).
  • Hey Guys, thanks for the replies. I removed the rule that was said to only be effective in Bridge mode, as I'm trying to set this up as a Gateway. I tried messing with the machine again last night, with the same result.
    My Port 3 interface for WAN states: Connected 100Mbps - Full Duplex Auto-negotiated.
    IP - NA
    DHCP

    I tried removing the greyed out "128.0.0.1" for the Gateway IP, but that didn't make a difference.
    I also set this interface up statically with the outside address I receive currently from my working Firewall(clearos). Set up statically, I'm not able to get to the outside.


    I tried changing my MAC address to possibly show the ISP the machine or adapter has changed. That didn't help either. At this point I'm actually just swapping the hard drive out of the machine that's working as my Firewall, with the Sophos XG configured one.... I wish I could get this to work. I would love to be able to use the features included. Also, I love the UI. If anyone has any other ideas, please let me know. I've rebooted... I've also power cycled my ONT, with no luck as well. Thanks all.

  • I had to force a release from my FIOS router. Thanks for the replies everyone.
  • Hey Rob. In future, please don't remove the text of the original post when your issue is solved. Maybe this thread could have helped someone else in future, but now people won't know what the original issue was.  These forums are a community.  It's not just about helping individuals, it's about helping everyone, past, present, and future.  

    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1
  • No problem. I'll add it back. I did this until I figure out how to rename my user name. At this point, I don't see it being possible.
  • Thanks Rob. Rename is something an admin will need to do, if allowed.
    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1