This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New and lost? Want to add a switch, and a wireless AP (old router) 9.404-5

Hey all, 

My router was recently hacked so I've gown down a whole new path of trying to get a more sophisticated home network security setup going.   

I'm off to a fairly good start I think after getting this all installed but I'm stumped on the network setup?

I managed to get UTM 9.404-5 installed. I've got a old HP box that I put a 128gb SSD in and loaded it up on.  I bought 3 3xtra TP-Link Cards so I have 4 ports on the back. 

I'd "like" to have;

1. nic hooked up to a single Primary Desktop that i can use to do work on or banking and such not casual browsing more secure separate from the rest of my network.

2. nic hooked up to a 8 port switch that I can wire into my other PC,s and Video Games, other peoples laptops that want wired connnects for other people to use, watch TV on use the computer, etc

3. nic hooked up to an old netgear router (converted to AP) so that I can use it for wireless with a secure password but separate from everything else.

4. nic ... not sure what to use this for yet, open to suggestions!

So far I've got UTM hooked up and I'm working off the only nic / computer I can get to work.  

I tried to add the switch in, but I'm sure I'm doing it wrong?  

My current settings are: 

WAN [UP] on eth3  [ip i'm guessing assigned by time warner] (I'm not sure if the IP matters here or if it's safe for me to post it)
MTU 1500  DEFAULT GW [guess assigned by TW]    . 

Internal [UP] on eth0 [192.168.2.100/24]
MTU 1500 
auto-created on installation

D-Link Switch [DOWN] on eth2 [192.168.2.10/24]
MTU 1500

Router [DOWN] on eth1 [0.0.0.0/0]
MTU 1500

I would really appreciate any help I could get.  I appreciate it!



This thread was automatically locked due to age.
Parents
  • Hi Casey,

    I did not understand where are you facing trouble in setup. Did you check the getting started guide here.

    Please brief your requirement specifically. Concise information is useful to read and understand.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hey there,

    Thank you for taking a look at my issue.  I did go through the getting started guide successfully before posting.


    I believe I've got all that part set up, my problem is connecting other devices;

    I'm trying to add 2 more interfaces correctly, one connected to a Switch, and the other connected to a Router (converted to AP)

    The hardware is installed, but I'm not able to connect to either device (corded on the switch, or wirelessly on the AP)

    This is my current configuration in the interface module in the WebAdmin

    WAN [UP] on eth3  [ip i'm guessing assigned by time warner] (I'm not sure if the IP matters here or if it's safe for me to post it)
    MTU 1500  DEFAULT GW [guess assigned by TW]    . 

    Internal [UP] on eth0 [192.168.2.100/24]
    MTU 1500 
    auto-created on installation

    D-Link Switch [DOWN] on eth2 [192.168.2.10/24]
    MTU 1500

    Router [DOWN] on eth1 [0.0.0.0/0]
    MTU 1500

    I'm not sure what I need to do differently to get my switch to work on it's own interface? I didn't see a guide for that? 

  • Hi,

    I see you have a similar subnet for Internal and D-Link interfaces. What happens when you change the network subnet for Dlink interface? Also, are you able to get the Dlink switch UP on internal interface? I suspect it to be a hardware issue.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Like sachinguru also told, make sure to use different subnets for every ethernet interface you are using (especially while you want to completely separate this 1 computer from the rest.

    Also make sure to have masquerading rules for every interface that needs internet access (Internal, D-link switch and Router).

    You will also need to create a subnet on the Router interface, since you have your router configured as an Access point, it will most likely not hand out IP-addresses. You will then also need to check the IP-address of your Router (if manual) or setup a DHCP scope on the UTM. You may also need to create a DHCP-scope for the D-Link switch subnet.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Check #3.1 in Rulz, Casey.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data