Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web filter Double NAT

Good Morning

I have the following scenario double nat, and all web brand me as uncategorized.

Public IP-> Router (10.0.0.2) -> External Sophos IP (10.0.0.1) -> LAN (internal Sophos IP (192.168.0.1), Lan range (192.168.0.0/24)

First need to know if this is correct:
Cloud Server URL: coc.wing.sophosxl.net & peakcoc.wing.sophosxl.net (Port 80,443,6060 & 6061)

Which it is the second rule should configure for categorizing requests reach the Sophos

Currently I have this rule does not work.

Thank you



This thread was automatically locked due to age.
Parents
  • Diego,


    XG is able to reach the internet because rules for him are already opened. You do not need to create rules.
    I have the same installation as yours at home and you only need to create rules to allow traffic from internal to wan zone (network/user rules).

  • Good morning,

    Users within the network browse perfectly,

    The problem is that the web categorization does not work.

    All web to appear as Uncategorized.

    The problem is that XG query to the database categorization but the answer is not able to route the call to XG and brand as uncategorized.

    If I create a category by hand with a web if recognizing it.

    How do I solve it?

    a greeting

  • This is strange! Did you open all port on your router? All traffic is forwarded to your XG WAN Ip address?

    Does the URL category lookup works under System > Diagnostics ?

  • Good afternoon

    First of all thanks for your answers

    Currently the wan ip of the XG is placed in the DMZ router that lets me set.

    There is no rule no port forwarding Port Triggering.

    Should I create one?

    You have said that you have configured the same in your home, you can tell me the router configuration?

    The router that I have no bridge mode

    a greeting

Reply
  • Good afternoon

    First of all thanks for your answers

    Currently the wan ip of the XG is placed in the DMZ router that lets me set.

    There is no rule no port forwarding Port Triggering.

    Should I create one?

    You have said that you have configured the same in your home, you can tell me the router configuration?

    The router that I have no bridge mode

    a greeting

Children