• Can Successfully Traceroute from a VLAN subnet, but the subnet cannot use the internet

    Hi! Running an SSG330. I have a strange situation and I am a bit at my wits end. I have a subnet attached to a VLAN interface, which is applied on the Sophos LAN interface. I have setup masquerading for this subnet to the SSG330's External interface…
  • Trouble with masquerading

    I have a UTM 9.5 in the cloud. I connect to it with a L2TP over IPsec connection. I establish the connetion and visit some site to check my IP and it shows the IP of my UTM. If I drop the L2TP over IPsec connection and refresh it shows my work IP. So…
  • 2 machines sharing one WAN port and IP unintentionlly

    I have a physical machine (PM) with physical ports eth0 and eth1. It is running a virtual machine VM0 via KVM. As consequence, eth0 appears aliased to virbr0, such that the only ports that are "up" are eth1 and virbr0. Other VM's lay behind VM0, which…
  • DMZ, VPN Client, Routing, FW

    DMZ, VPN Client, Routing, FW Hello, I would like to setup a router (VPN Client) in a DMZ and route traffic from LAN over DMZ to Open VPN Tunnel. I have the following configuration till now: WAN Interface (Ethernet) : 82.x.x.x LAN: 192…
  • UTM 9.502-4 : Unable to route to Internet from LAN port but able to from (3rd NIC) i.e. Management

    Hi, sorry, newbie question alert. Set-up UTM 9.502-4 running on "small" PC brick with 3 NICs (Eth0 is hardwired, Eth1 and 2 are USB <> Ethernet dongles) Eth0 (Management NIC) has 192.168.10.250 Eth1 (ISP interface) Eth2 (LAN interface) has…
  • DNAT, SNAT or Masquarading - Not for a server - GFE Client (Good For Enterprise)

    Hi, I run a Sophos UTM 9 at home which I've been running for well over a year now and it's been very good. I have a stack of firewall rules for various devices and I've configured various rules for things like cameras and VOIP phones. My recent…
  • DNAT config issues when blocking access to internal network from VPN

    Hi guys, Hope this finds you well, I'm having issues configuring a DNAT correctly. The end goal is to create a full tunnel SSL VPN profile that has access out to the internet only, denying all connections to the local network. This topic has…
  • Can't access internal website over VPN using WAN-accessible FQDN

    I have a small home network protected by Sophos UTM 9.3. The ISP-assigned WAN address is resolvable (using DDNS) to an FQDN--call it mydomain.com. Within this network, I have a web site running on TCP 8080. This is reachable from the WAN via a DNAT rule…
  • Routing configuration for DMZ Help !

    Hi, i'm a noob with UTM ASG 220 at this time. I have to configure a DMZ with a dedicated ADSl link and i'm not able to do that... My ISP gave me a /30 pool adresses for my router and told me that the UTM should to do NAT rules: 122.255.175.210/30…
  • Implied NAT?

    Hi All, I'm approaching the end of a 30 day evaluation of Sophos UTM Software Appliance (Version 9.355.1) and have a query that maybe someone will be able to clear up for me in relation to Network Address Translation. I have set the default gateway…
  • Router behind Sophos UTM

    Hi, I have clients behind a router behind a sophos UTM which I am trying to get internet access but not sure where to go from here. My setup is below: Sophos UTM Connected to Modem (which connects to internet) LAN IP address of 192.168.1.1/30…
  • Branch Office connected via MPLS, can't get to internet.

    I Just hooked up a branch office up via MPLS and I am a bit stumped I have a Laptop plugged in on the Branch office MPLS router, it sees my main office, and vice-versa, but I can't get to the internet from the branch. I added a static Gateway…
  • RDP of a Windows computer through UTM 9.3 between multiple subnets?

    I have published several RDP targets through my UTMs over the years, but this particular one seems to have me stumped. So, here is my layout. Internet -->Router (Subnet 1)-->UTM--(Subnet 2) Subnet 1 houses all of my General use items (WiFi TVs, Game…
  • Multiple ISPs active with Masquearding

    I have been looking for a solid answer for this for 2 days now and have come up empty handed. We had a single ISP and all of my masquerading rules were working fine. I purposely put the IT VLAN out on a different external IP address compared to normal…