<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Lan to Wifi separate zone not working</title><link>https://community.sophos.com/sophos-xg-firewall/sfos-v18-early-access-program/f/feedback-and-issues/118068/lan-to-wifi-separate-zone-not-working</link><description>Hi i have a wifi separate zone for security cams. 
 I cant ping or connect from LAN &amp;#160;to the separate zone wifi network. 
 It was working in v17. 
 Check out some Screenshots. 
 The firewall rule should work but it doesnt. 
 Weird that no firewall log</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427773?ContentTypeID=1</link><pubDate>Wed, 05 Feb 2020 05:42:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0e0076e2-1cc7-4745-a721-2fdaf5ed1c4b</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;you are lucky to get it working. I had to delete mine because I was getting too many IPS hits even with IPS with disabled and DOS unticked and finally ATP disabled.&lt;/p&gt;
&lt;p&gt;So, back to another reconfigure to get IoT devices working, so another AP installed to isolate the devices to their own physical network.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427737?ContentTypeID=1</link><pubDate>Tue, 04 Feb 2020 17:33:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1fad8541-9391-4e44-8f48-6232bd7808f7</guid><dc:creator>Mario Ostwald</dc:creator><description>&lt;p&gt;Thanks to Mr Patel added some static routes over cli and now it works as a workaround. Will be fixed in v18.GA.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427457?ContentTypeID=1</link><pubDate>Sat, 01 Feb 2020 09:37:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1c6fd354-e83d-44fc-8f85-bfaa44c8bc37</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;using the SD-WAN policy allows me to get the LAN to separate zone working, just you have to have a WAN entry.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427455?ContentTypeID=1</link><pubDate>Sat, 01 Feb 2020 09:24:02 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:14aa6e88-616a-44fa-98b5-80f437f49a40</guid><dc:creator>Mario Ostwald</dc:creator><description>&lt;p&gt;Yes i see no drops, too. You use the sd wan policy for the routing to the separate zone? Wan is not my problem.&lt;/p&gt;
&lt;p&gt;LAN -&amp;gt; Wifi in separate zone doesnt work.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427446?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 23:58:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4ac7bf33-83fa-47f1-a672-f635ae00507c</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;I have found a temporary solution, it works but not very well. I setup an SD-WAN policy route which has some strange requirement to use an the XG external gateway for internal traffic and you cannot ignore the setup. Also the help information when you move a mouse over the objects is useless and needs to be brought up to the same standard as other policy/rules.&lt;/p&gt;
&lt;p&gt;In the migrated sd-wan policies you are shown a firewall rule, but only of the external access, there are no sd-wan policoes created during migration for the internal access firewall rules.&lt;/p&gt;
&lt;p&gt;SD-WAN only allows one session where as a firewall rule allows multiple sessions to the same device. Throughput while I can&amp;#39;t test and provide actual values is just plain painfully slow.&lt;/p&gt;
&lt;p&gt;I tried using the Static routing and that is just plain silly/not logical, you must have a gateway that is in the same IP range as your interface, they are the same thing. so that doesn&amp;#39;t work.&lt;/p&gt;
&lt;p&gt;In the end v18 GA should make all this SD-WAN routing redundant when the fixes are applied.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;
&lt;p&gt;The setup to fix the bug, does leave a question about the migrated SD-WAN policy, why were they created, what is missing that needs to have these put in place?&lt;/p&gt;
&lt;p&gt;More thoughts on this subject, there is no way of seeing what traffic is passed though the SD-WAN policy (no logs) or how much?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427384?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 10:22:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:12dace28-7d05-4294-a6aa-c2458855933e</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;not that I have found yet, I am still in the process of fixing a number of items I broke during the migration from VLANs.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427362?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 08:20:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ed4e08f7-35a6-4090-9693-fde241bff97d</guid><dc:creator>Mario Ostwald</dc:creator><description>&lt;p&gt;Hi Ian, so you can reproduce the problem as well? Is there any workaround this?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427348?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 05:52:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0f05ba07-dc3c-49dc-a027-0be0fb3754f6</guid><dc:creator>GavinDaniels</dc:creator><description>&lt;p&gt;Hey Ian,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You are correct, I tested that as well.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;And it is not an issue related to V17 migration, as I reset my XG125 to factory defaults after EAP3R1 and have set it up completely from scratch. No backup import.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427346?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 05:49:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ec8a1a32-2049-4edb-bdb7-617fb0320f6c</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Doesn&amp;#39;t make any difference if it is a WIFI or seperate zone.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427316?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 00:38:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d35b6c4d-c95e-4fc5-8543-18da9b70eabc</guid><dc:creator>GavinDaniels</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Just set up a test, and actually seeing what I expect is the same result as you.&lt;/p&gt;
&lt;p&gt;Basic setup,&lt;/p&gt;
&lt;p&gt;Created new &amp;#39;LAN&amp;#39; Zone for Wifi&lt;/p&gt;
&lt;p&gt;Created Wifi SSID as new zone, client isolation disabled.&lt;/p&gt;
&lt;p&gt;Created firewall rules for Lan to Wifi Zone and seperate rule for Wifi Zone to Lan&lt;/p&gt;
&lt;p&gt;DHCP for Wifi Zone done on Sophos&lt;/p&gt;
&lt;p&gt;All services allowed&lt;/p&gt;
&lt;p&gt;From the Wifi devices (ipad, Iphone, Laptop) I can ping each other, and I can ping anything on the LAN (PC, NAS, ECT)&lt;/p&gt;
&lt;p&gt;From the Lan devices or the Sophos Firewall I cannot ping a device on the Wifi Zone&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I also tried setting the Wifi setup back to the default WIFI zone, still no go.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I believe that the Wifi Zone is right, because I have a seperate WIFI Zone to WAN rule, and after changing the WIFI SSID to the default WIFI zone, then I lost internet access on the Wifi Devices.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So I will agree with you, an introduced bug in V18&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/277/APConfig.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/277/APConfig.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/277/WifiSetup.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/277/WifiSetup.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/277/WifiGroup.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/277/WifiGroup.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/277/Rules1.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/277/Rules1.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427314?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2020 00:14:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:aafca83e-6ae5-4d35-a765-b98b3ec67589</guid><dc:creator>Mario Ostwald</dc:creator><description>&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/277/Screenshot_5F00_20200131_2D00_011243_5F00_Chrome.jpg"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/277/Screenshot_5F00_20200131_2D00_011243_5F00_Chrome.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;here is the other direction.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427306?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2020 23:21:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:935a6838-25d0-4def-8693-e55ac4b460dc</guid><dc:creator>GavinDaniels</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Can you please post your other rule.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427305?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2020 23:16:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ab5e625a-bf05-49a0-93da-e916c49d64ea</guid><dc:creator>Mario Ostwald</dc:creator><description>&lt;p&gt;That is not the problem, i have added a rule for the other direction, too.&lt;br /&gt;I think it must be a bug...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427261?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2020 14:24:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dee91656-9eb4-41d6-ac78-c795847d5694</guid><dc:creator>Apurv Patel</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Thanks for device access and live debug session.&lt;/p&gt;
&lt;p&gt;We are tracking this issue with Jira ID NC-55640.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427243?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2020 13:19:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f0f31ef8-5740-4bd5-8877-4b74fd272cbc</guid><dc:creator>GavinDaniels</dc:creator><description>&lt;p&gt;Hey&lt;/p&gt;
&lt;p&gt;That is a rule for one direction.&lt;/p&gt;
&lt;p&gt;Where is the return rule to allow the WifiRestricted traffic back to the Lan?&lt;/p&gt;
&lt;p&gt;It may be included in another rule, but if you upgraded from V17 to V18 the return rule may have been lost.&lt;/p&gt;
&lt;p&gt;I did notice that my initial V18 upgrade lost some rules.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Lan to Wifi separate zone not working</title><link>https://community.sophos.com/thread/427215?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2020 10:08:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0e6f7f2e-c3db-4fe8-92ee-ad0e9f4f6295</guid><dc:creator>Apurv Patel</dc:creator><description>&lt;p&gt;Hi Mario,&lt;/p&gt;
&lt;p&gt;&amp;nbsp; &amp;nbsp; Thanks for your feedback, I will send you PM for more details purpose.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>