This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Interface communications not working

Hello all... New to Sophos

I'm very excited to have found this free UTM for home use as I simply do not feel I am in control of my home network. I have set up the Sophos on a Dell Optiplex 780 (I think) and added NICs to a total of 6 interfaces. 

What I am trying to accomplish is a segregation of certain devices by implementing separate networks as follows:

Sophos eth0: WAN IP 192.168.2.2 GW 192.168.2.1 (Bell Home Hub 2000 with NO bridge mode)
Sophos eth1: LAN IP 10.10.1.1 DHCP range 10.10.1.10-10.10.1.50

This all works fine...until I want to add a router for WiFi which I have attempted to set up as follows:

Sophos eth2: WiFi IP 192.168.1.2
WiFi WAN: 192..168.1.1 GW 192.168.1.2
WiFi LAN IP: 10.10.1.2 
WiFi DHCP: 10.10.1.60 - 10.10.1.90 GW 10.10.1.2

With this config, I am unable to allow any wifi device access to the LAN or internet on the Sophos. I can ping the Sophos eth2 at 192.168.1.100. I'm sure I am not configuring something correctly here. Ideally I would like the WiFi IP network to be 10.10.2.0 (I used the 10.10.1.0 network to see if that at the very least let me communicate to the Sophos LAN segment. 

This is the first step I need to resolve before proceeding with the remainder of the configuration... and I clearly need some help as I have been ripping my home network apart and have since reverted everything back to my Bell Home Hub 2000....and I am slowly dying. I work with NextGen Firewalls daily, and I can't figure this one out. I am completely tunnel visioned and need someone to remove the blinders for me.... it's embarrassing. 

Thank you in advance. I have gotten really helpful feedback on another post from this forum and hope to able to contribute to solutions more than problems in the future. 

Cheers



This thread was automatically locked due to age.
Parents
  • Hi Andrew,

    in this construct you must allow the Internet and LAN access for the WAN IP of your WiFi router in the UTMs firewall. Because all WiFi clients will be NATed and therefore they will come with the WAN IP of the WiFi router through the UTM.


    I aggree to Bobs suggestion. Disable DHCP on the WiFi router, put it into bridge mode or attach the WAN cable to a LAN port of the WiFi router. Enable the DHCP server for the WiFi interface eth2 on the UTM, and change the IP subnet to 10.x.x.x or whatever you want.

    Jas Man

Reply
  • Hi Andrew,

    in this construct you must allow the Internet and LAN access for the WAN IP of your WiFi router in the UTMs firewall. Because all WiFi clients will be NATed and therefore they will come with the WAN IP of the WiFi router through the UTM.


    I aggree to Bobs suggestion. Disable DHCP on the WiFi router, put it into bridge mode or attach the WAN cable to a LAN port of the WiFi router. Enable the DHCP server for the WiFi interface eth2 on the UTM, and change the IP subnet to 10.x.x.x or whatever you want.

    Jas Man

Children