This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED and multiple Subnets

Hello,

perhaps someone can help me with this configuration:

We have a location connected to our UTM via RED which now needs a second subnet as DMZ and there will be a port forwarding from our UTM to this subnet. Today we have only one subnet with a simple setup at this location, so is this configuration possible?


Example:

UTM (192.168.0.254) ->

RED (Port 1) -> 192.168.1.254
RED (Port 2) -> 192.168.2.254

We want to setup the port forwarding on the UTM. In addition to that a direct access from the internal LAN on the remote site (Port 1) to the DMZ (Port 2) should be possible for some services (packet filter).



This thread was automatically locked due to age.
  • With a RED, you have to use VLANs.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • There is a RED 50 is necessary, isn't it?

    Does the traffic between the VLANs pass the UTM via the slow WAN or is it a direct route between the two VLANs based on the packet filter rules configured on the central UTM for these two VLANs?

  • I guess, traffic will go trough the RED Tunnel twice, because the DGW is located at the UTM's site, which is on the other End of the RED.

    From my understanding, there will not be any routing on a RED Device directly.

    Please send me Spam gueselkuebel@sg-utm.also-solutions.ch

  • Rather than a RED 50, I would use an XG 85 with V9,4 and Network Protection subscriptions.  However, you can define VLANs directly on the RED 10 interfaces.  You would want a VLAN switch behind the RED, I think.  If you try without a VLAN switch, please tell us your results.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA