This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Wireless Controller

Hi,

 

Can the Sophos XG Firewall (XG 135v3) be used as a wireless controller only?

If yes, how should the configuration be?

 

Previous situation: XG 135 as Gateway to the internet with 2 AP100c bridged to LAN. (1 Guest and 1 User LAN)

Now: Other Router/Firewall as Gateway to the internet. Uplink to Coreswitch with multiple VLAN's. The XG 135 is now connected on the MGMT VLAN.

 

Let's say I have 3 vlans on the new gateway to the core switches.

Vlan 10 = MGMT

Vlan 20 = Users

Vlan 30 = Guests

 

How should the trunk towards the AP's be configured like? If I choose to bridge to VLAN it says I have to configure an AP MGMT VLAN. (so no untagged vlan supported when using "bridge to vlan" for management?)

How should the connection to the XG be configured like? Does all traffic going over the AP's need to pass over the XG or can I use the XG for controlling the AP's only (which would be great)?

 

Thanks for your reply

 

Best regards,,

Simon



This thread was automatically locked due to age.
Parents
  • It was working as follows:

     

    Configuration on the XG:

    1 interface with a dummy IP address for untagged traffic.

    1 subinterface on the above with an IP address configured in the MGMT Vlan.

    1 static route 0.0.0.0/0.0.0.0 because no default gateway can be configured on the subinterface.

    1 rule: any to any for any

    2 wlan networks: 1 for guest (bridge to vlan) and 1 for users (bridge to vlan)

     

    Configuration on the interfaces to the AP:

    Trunk with No untagged vlan and 3 VLAN's tagged.

     

    It works but it's oh so slow and I don't think it's the way to go..

Reply
  • It was working as follows:

     

    Configuration on the XG:

    1 interface with a dummy IP address for untagged traffic.

    1 subinterface on the above with an IP address configured in the MGMT Vlan.

    1 static route 0.0.0.0/0.0.0.0 because no default gateway can be configured on the subinterface.

    1 rule: any to any for any

    2 wlan networks: 1 for guest (bridge to vlan) and 1 for users (bridge to vlan)

     

    Configuration on the interfaces to the AP:

    Trunk with No untagged vlan and 3 VLAN's tagged.

     

    It works but it's oh so slow and I don't think it's the way to go..

Children