This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Add eth2 and make it vlan?

What is the best and easiest way to switch over to using vlans on UTM with out getting rid of the eth0 or keeping eth0 as a regular network interface?

I want to use a 3rd network interface (eth2) of a VLAN interface and have it replace the eth0, but keep eth0 as configured by wizard and have all LAN local traffic run on the VLAN and Vlan interface.

using UTM ver. 9.4

Years ago I was able to get my UTM eth0 switched to a VLAN interface on the Physical machine.

Trying to build the same UTM as a VM on ESXi 5.5 is another story. So the question is, if I get the UTM working fine in the VM with the basic wizard install, where eth0 is the LAN regular /24 network interface, eth1 is the WAN, and then bring up / set eth2 as a vlan interface and then stop using the connection from eth0 and just use the vlan interface eth2 for everything.

I was trying this on the VM and was able to create the eth2 interface for vlans and set up vlans and seemed to ping them fine but when I removed the eth0 connection and tried to use the eth2 vlan interface and vlan 10 for everything, (it was moved to a trunk port on the switch and not one set to access)  I could not get out to the Internet. I thought I had the rules to allow the vlans to access / go out the WAN connection and the DHCP on the vlans was working from Sophos.  But just not able to get it to route or for the vlan 10 to pass out to the Internet. If you have only 2 nics, you have to set UTM tobe able to be managed from the WAN / eth1 connection so you can be logged in and remove eth0 and bring it back as a vlan interface on eth0 with the vlans assigned to it. I have 4 network ports to work with so I thought just after basic default setup to then just make eth2 a vlan interface and then turn off eth0 and let all internal LAN / Vlans traffic use eth2. 

 

What is the best order of operation, to accomplish this?

I seems once you switch the UTM over to vlan interface, trying to go back or build a VM using the vlans is not easy. All the switches currently have all access ports set to vlan 10 and the uplinks are all trunked. So even with the VM set with regular network interface and only one /24 network, I can disconnect and reconnect between the Physical utm and the VM UTM for testing and I make sure the LAN connectionis in the correct access or trunk port of the switch when testing between the machine and the vm.  I am a home user, with the home version, and for my learning and home network, I use Vlans. ( I do want to set up test networks and isolate my DVR I.P. camera traffic from the regular LAN traffic in the house so why I have vlans set.

Just now trying to get the VM set up to work  with vlan interface configuration.

Chad

 



This thread was automatically locked due to age.
Parents
  • If you don't have internet access you may have forgotten to create a Masquerading rule so to masquerade your VLAN internal IP to the External IP of your internet connection.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Reply
  • If you don't have internet access you may have forgotten to create a Masquerading rule so to masquerade your VLAN internal IP to the External IP of your internet connection.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Children
  • Hello, That might be the issue. This week I will have to try that. I did not set up a Masquerading rule, Just the firewall rule that let each vlan access the WAN network.

    Thank you for the information.

  • Saturday I read over all the posts, and found a few posts that offer some Masquerading rules. I have asked a question to see if I can add Vlans to the default network LAN interface and still have my 172.16.16.16 which I assume is on vlan 1 or the default vlan and then just add additional subinterfaces for like vlan 10 and vlan 11 and so forth to the same interface A, / LAN interface.

    Thank you for the information and suggestion, going from UTM 9 to Xg v16, is like learning to ride a bike all over again.

    Chad