This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internet access not working

Hi,

Ive run into two main issues while setting up my Sophos UTM. Any help would be greatly appreciated.

1. No internet access

2. Inter-vlan routing doesnt work. 

I am running Sophos from my QNAP with a Cisco SG300 L3 switch. DHCP is provided by Sophos and is working great. From every vlan on the switch i can ping the default GW (172.20.99.1) and access the management page of Sophos.

My internet PPPoE is set to the External WAN interface and connects to my provider successfully. From Sophos i can ping out with no issues. From my switch using my transit vian 99, i can ping out with no issues. But from a pc on vlan 99 im unable to ping out. Also if i connect to the switch under any other vlan im unable to ping out from the switch or the pc on that vlan. I have also tried (any -  any - any) firewall rules but this doesnt make any difference. I have masquerading and firewall rules to get out to the WAN and allow access between vlans.

My switch is using port 28 as a trunk port with all vlans tagged bah the native vlan 99. Each vlan has a default ip address set to 172.20.x.1. The switch has a 0.0.0.0 route to Sophos on 172.20.99.1.

Im not sure if there is something im missing while configuring Sophos or if ive missed something on the switch. 



This thread was automatically locked due to age.
Parents
  • Hi, David, and welcome to the UTM Community!

    In general, pinging is regulated on the 'ICMP' tab of 'Firewall', but pinging between local networks requires a firewall rule like 'Any -> Ping -> Any'.  Note that the 'Any' Services object only includes the TCP and UDP protocols.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, David, and welcome to the UTM Community!

    In general, pinging is regulated on the 'ICMP' tab of 'Firewall', but pinging between local networks requires a firewall rule like 'Any -> Ping -> Any'.  Note that the 'Any' Services object only includes the TCP and UDP protocols.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children