This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM not communicating Vlans, how to add Static Route?

Hi there,

We have Cyberoam NG firewall at office, very soon we will upgrade to Sophos.

While this Cyberoam Firewall sits on Gateway for our network, it does DHCP things, we have Vlans, so it does Inter-VLANs routing as well.

I setup virtual Sophos UTM free one to test VPN features and connected directly to ISP router and to internal network as well.

Now problem is, this UTM have no communication with Vlans, while no other devices has issues, I think UTM has issues because, UTM is not communicating with Cyberoam Firewall which is doing Inter-VLANs routing. All working fine, when I connect one network card from each network.

I believe, adding static route to vlans will do the trick? without requiring to add multiple network cards?

If so, which Linux does Sophos run on? Or maybe it has its own? Anyway, just need to understand how to add permanent static route.

Appreciate your responses.

Thanks!



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi  

    Thank you for reaching out to the Community!

    Steps to add static route form the UTM WebAdmin:

    1. Login to the WebAdmin and go to Interfaces & Routing | Static Routing | Standard Static Routes 
    2. Click New static route...
    3. Choose Route Type: Gateway route.
    4. Under Network, add the network object for the network you want to reach.
    5. Under Gateway, add the object for your recently created Availability Group.
    6. Click Save.


    Standard Static Routes: 


    The system automatically inserts routing entries into the routing table for networks that are directly connected to the system. Manual entries are necessary in those cases where there is an additional router that is to be accessed via a specific network. Routes for networks, that are not directly connected and that is inserted to the routing table via a command or a configuration file, are called static routes.

    • To add a standard static route, proceed as follows:

              1. On the Standard Static Routes tab click New Static Route.

                  The Add Static Route dialog box opens.

              2. Make the following settings:

                  Route type: The following route types are available:

    Interface route: Packets are sent out on a particular interface. This is useful in two cases. First, for routing on dynamic interfaces (PPPClosed), because in this case the IP address of the gateway is unknown. Second, for defining a default route having a gateway located outside the directly connected networks.

    Gateway route: Packets are sent to a particular host (gateway).

    Blackhole route: Packets are discarded silently. This is useful in connection with OSPFClosed or other dynamic adaptive routing protocols to avoid routing loops, route flapping, and the like.

    Network: Select the destination networks of data packets Sophos UTM must intercept.

    Interface: Select the interface through which the data packets will leave Sophos UTM (only available if you selected Interface Route as route type).

    Gateway: Select the gateway/router to which Sophos UTM will forward data packets (only available if you selected Gateway Route as route type).

    Comment (optional): Add a description or other information.

             3. Optionally, make the following advanced setting:

    Metric: Enter a metric value which can be an integer from 0 to 4294967295 with a default of 5. The metric value is used to distinguish and prioritize routes to the same destination. A lower metric value is preferred over a higher metric value. IPsec routes automatically have the metric 0.

             4. Click Save.

                  The new route appears on the Standard Static Route list.

             5. Enable the route.

                 Click the toggle switch to activate the route.

                 To either edit or delete a route, click the corresponding buttons.

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi  

    Thank you for reaching out to the Community!

    Steps to add static route form the UTM WebAdmin:

    1. Login to the WebAdmin and go to Interfaces & Routing | Static Routing | Standard Static Routes 
    2. Click New static route...
    3. Choose Route Type: Gateway route.
    4. Under Network, add the network object for the network you want to reach.
    5. Under Gateway, add the object for your recently created Availability Group.
    6. Click Save.


    Standard Static Routes: 


    The system automatically inserts routing entries into the routing table for networks that are directly connected to the system. Manual entries are necessary in those cases where there is an additional router that is to be accessed via a specific network. Routes for networks, that are not directly connected and that is inserted to the routing table via a command or a configuration file, are called static routes.

    • To add a standard static route, proceed as follows:

              1. On the Standard Static Routes tab click New Static Route.

                  The Add Static Route dialog box opens.

              2. Make the following settings:

                  Route type: The following route types are available:

    Interface route: Packets are sent out on a particular interface. This is useful in two cases. First, for routing on dynamic interfaces (PPPClosed), because in this case the IP address of the gateway is unknown. Second, for defining a default route having a gateway located outside the directly connected networks.

    Gateway route: Packets are sent to a particular host (gateway).

    Blackhole route: Packets are discarded silently. This is useful in connection with OSPFClosed or other dynamic adaptive routing protocols to avoid routing loops, route flapping, and the like.

    Network: Select the destination networks of data packets Sophos UTM must intercept.

    Interface: Select the interface through which the data packets will leave Sophos UTM (only available if you selected Interface Route as route type).

    Gateway: Select the gateway/router to which Sophos UTM will forward data packets (only available if you selected Gateway Route as route type).

    Comment (optional): Add a description or other information.

             3. Optionally, make the following advanced setting:

    Metric: Enter a metric value which can be an integer from 0 to 4294967295 with a default of 5. The metric value is used to distinguish and prioritize routes to the same destination. A lower metric value is preferred over a higher metric value. IPsec routes automatically have the metric 0.

             4. Click Save.

                  The new route appears on the Standard Static Route list.

             5. Enable the route.

                 Click the toggle switch to activate the route.

                 To either edit or delete a route, click the corresponding buttons.

    Thanks,

Children
No Data