Browse By Tags

  • Which is better, connect POE switch (for APs) direct to firewall port? Or to Cisco switch, then from Cisco to firewall?

    Currently, I created Vlans for my each SSID of my Unifi APs. I have 4 APs, all connected to my TP-Link poe switch, which is Vlan aware also. The poe switch is plugged to my Cisco switch e.g. port 10 (Vlan aware). All other desktops (not in Vlans), NAS…
  • Modification of the interface MTU

    Hi all! Quick question regarding XGS 126: MTU is a property of the physical interface. If I want to reduce the MTU for a VLAN I have to do it on the physical interface. By adjusting MTU value I seem to lose the VLAN interface and the associated dependencies…
  • Sophos sg105 UTM 9 - VLAN setup

    Hello, I am going to rent an office space to an external company. I have to separate the network so that the tenant does not reach our internal resources. can i set up vlan to separate? if so, how is this done?
  • Routing Problem on XG19.0.0

    I have a problem where I am unable to ping google and it somehow seems as the firewall is missing a route back to my client. My client is inside a VLAN (172.16.87.99) and from the traffic below I can see that it correctly routes to the gateway address…
  • Gleiches VLAn an mehreren Eth-Schnittstellen

    Hallo zusammen, ich habe das gleiche VLAN auf zwei verschiedenen Eth-Schnittstellen und die sollen miteinander reden können. Muss ich dann für jede Eth-Schnittstelle eine VLAN-Schnittstelle erstellen und diese dann gruppieren? Ist das korrekt oder…
  • VLAN on WAN Port

    Hello, i have a problem with the internet connection on physical port WAN with additional vlan (zone LAN). I tried to change the physical port to an dummy ip and zone DMZ and create two vlans 1 (WAN) and 40 (LAN). My router recognizes the IP address…
  • Whitelisted Access to Internet for vLAN - Sophos Firewall

    Hi, We have just started using Sophos FW and having some difficulties creating Rules. We have two vLANs vLAN10 and vLAN20. We need to allow vLAN10 to have full access to the internet whereas vLAN20 should have a whitelist, i.e. access to few websites…
  • ROS Sophos

    Hi, I'm new with this equipments, i'm trying to configure VLANS between two equipments (SOPHOS -» Switch) SOPHOS: - WAN - DHCP from ISP router - LAN PORT1 IP: 192.168.100.1/24 - ZONE LAN 1.10 - VLAN 10 - 192.168.10.1/24 - PORT 1 - ZONE…
  • How many maximum VLANs support in XGS3100 and XGS4500 ?

    How many maximum VLANs support in XGS3100 and XGS4500?
  • MY VLAN not working

    Dear Sir, i have already configure VLAN but i am not able to connected vlan to lan can you please help us and resolve this issue asap
  • Multicast with 2 Networks

    I have a SG135 with UTM Home and a Fritzbox 6591. My Network is a followed: ETH0: WAN with IP 172.10.0.2 (Fritzbox 172.10.0.1 / Additional IP 192.168.3.1 with DHCP on UTM for WLAN over Fritzbox) ETH1-7: internal Network with 192.168.4.1 and DHCP Pi…
  • SFOS 19.5 (virtual appliance) VLAN Problem

    Hi, I'm trying to get my Guest WiFi VLAN working on SFOS. This was previously working fine with UTM9 but since moving to SFOS has stopped working! Running the SFOS virtual appliance in ESXi v8, configured as follows; vSwitch0 contains port groups…
  • SD-WAN for VLAN

    We have a separate VLAN set up and working for our Guest Wifi network. Clients (mostly cell phones) receive a DHCP IP in the correct range, are segregated from any other network communication, and can get to the internet fine. What we would now like to…
  • Unable to access vlans from main network

    I have 2 Vlans on my network, 1 for voip and one for manageing devices such as swithces and accesspoints. until recently i was using a different router and that worked fine however sincce switching i am unable to access the vlans on th email network…
  • How to create a trunk between my Sophos Firewall XG X3300 and my Watchguard M410 ?

    Hello all, Currently, we need to migrate our existing Firewall Watch Guard Router whose license will expire soon by the Sophos Firewall. So we ask for your help to set up a trunk between these two routers, indeed the idea is that the Sophos will play…
  • How to create a Lan trunk between the Sophos XG Firewall and the Cisco Router ?

    Hi All I would like to create a Lan trunk between the Sophos XG Firewall and the Cisco Router This is my topology Could you please help me
  • (XG) VLAN traffic showing up on unexpected interfaces

    Hi all, User Kyle Sexson had this issue a while ago, too, but there’s no solution in his post - so… I have a set of VLANs running on a bridge interface. This works mostly well, but certain outgoing traffic will show up both on the bridge interface…
  • Setting up IP Camera VLAN

    Hello, I'm new to Sophos and can't seem to figure out what I'm doing wrong. I created a separate VLAN (Port 1.50) to prevent my IP cameras from accessing the internet and added the VLAN to the default "Traffic to WAN" group, rejecting any internet traffic…
  • XG - limiting traffic from one VLAN to another

    My setup has 2 VLANs - Main and IoT, using Sophos XG as DHCP and gateway. I'm able to allow traffic between the 2 VLANs by adding a firewall rule of LAN Any host Any service to LAN Any host Any service. What I'm trying to do is to only allow traffic…
  • VLAN subnet extension. New addresses unusable.

    Hi, I have increased the size of a subnet from /27 to /26 and any node with an IP beyond the range of /27 has connectivity issues. I have done this before and don't remember having issues. Apart from Network > Interfaces > VLAN > {Port} > IPv4/netmask…
  • Need to pass IPv6 Connectivity to a VLAN, many VMs need to be reachable from the Internet on port 161

    I see an IPv6 address on my WAN port, but none on any of my configured VLANs or Interfaces. I'm guessing I need to configure IPv6 Router Advertisements, but when I click it doesn't have an interface I'm not sure how to open this port up for these…
  • WOL not working with VLANs

    Hi, currently I use the SG105 running UTM 9.511 and I connect by SSH to Terminal of the UTM and execute the following Command as root. Commmand: /usr/sbin/ether-wake -i NIC ---MAC--- (Example: /usr/sbin/ether-wake -i eth0 00:00:00:00:00:00) this…
  • Creating Firewall Rules for Sophos Central Guest Network

    Hi, I have replaced the UTM with an XGS. I added the existing older access points to Sophos Central. The guest network under Settings Client Addressing is in Nat Mode. Is it only possible to create firewall rules for the guest network, when making…
  • Sophos UTM HA Cluster Slave-Node erkennt Master als dead und hohe CPU Auslastung

    Hallo zusammen, in meiner Firma haben wir ein Aktiv-Passiv-Cluster aus 2 SG230, die je ein "4x 10 GbE SFP+ FleXi Portmodul [SGIZTCHF4]" eingebaut haben. Vor kurzem kamen neue VLANs und neue Switche (25GBit) dazu. Die neuen Switche sind am Portmodul…
  • VLAN/DMZ interface IP as DNS Server

    Hi, I've set up a new VLAN (20) bound to the LAN hardware (Port1.20) with IP 192.168.20.1, and assigned it to the DMZ zone. If I run the policy checker using Firewall,SSL/TLS and web method, with the following parameters, it fails URL: dns://192.168…