This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Possible Network Config Issue - Two Subnets - One WAN - Proxy doesn't work on secondary LAN

I'll try to keep the details and summary short and sweet. Hopefully someone can point me in the right direction.

We just upgraded from an Astaro UTM to a Sophos SG330. We simply backed up the UTM config, uploaded it to the sg 330 and then applied the license file. Everything seems to have crossed over fine. I thought, for awhile that everything had gone smoothly. HOWEVER, we have no proxy on our secondary (remote) LAN. Any browser trying to pass through the proxy gets a browser "this page can't be displayed" message.

Network setup: 

INTERNET -> CISCOASA -> SG330 (eth1 and 0 bridged mode) -> Internal LAN1 -> Layer 3 Switch /Router -> LAN2

We have a direct fiber line to a building in another town that is on a different subnet. All routing between these two subnets is done behind the SG330 by a switch/router. 

Prior to the upgrade everything was great. An http request comes in from LAN2 hits the router and then passes through the SG330 (in bridge mode) on its way to the internet.

Now, the proxy doesn't work for LAN2. Works fine with LAN1 (the LAN it's "part of")

I hope that makes sense. Where do I start?

 

I can see this in the Network Log:

 

13:06:12 Default DROP TCP [PC on LAN2 IP] : 49596? [SG 330 IP Address] : 80 [SYN] len=48 ttl=127 tos=0x00 srcmac=[MAC] dstmac=[MAC]

 

Thanks



This thread was automatically locked due to age.
Parents
  • Is LAN2 actually allowed to use the webfiltering (Webfiltering -> Global -> Allowed networks)?


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Reply
  • Is LAN2 actually allowed to use the webfiltering (Webfiltering -> Global -> Allowed networks)?


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Children
No Data