This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Port Forwarding

Hi Sophos Community!

I am running Sophos XG Home, SFOS 18.0.1 MR-1-Build396.  I am trying to forward port 80 to my NAS, but so far have not been able to.

I have used the Server Access Assistant wizard to create the rules.  On my LAN I have no issues accessing my NAS with the loopback rule (using my DNS name) but I have not been able to access from the WAN.  Previously I had this all setup and working with my router.

I have followed this video:  https://vimeo.com/376241042, read numerous forums but it seems I am missing something perhaps not obvious.

  • It does not seem to be a DNS issue.  IP address also doesn't work.
  • Since I can access the NAS internally using the DNS name, this seems to indicate the NAS and network is fine.  Note that the NAS has firewall filtering capability but it has been temporarily disabled.
  • Note that the transfer data for the DNAT firewall rule is always 0 in and 0 out.
  • The NAT rule from WAN to the NAS usage count is also 0.
  • The loopback NAT rule usage count increments as I go to the NAS webserver from the LAN.

Any ideas?

Let me know if further info is needed.

Thanks.



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks for your help .  I did a packet capture and there was no sign of any incoming packets.  I reverted back to using my router and it also doesn't work.  I've started a ticket with my ISP.

    Thanks again.

  • I decided to continue this thread since the issue I'm having is related.

    When I try using a custom service that contains multiple services in a NAT rule, the inbound packets are rejected with status Violation, Local_ACL.  If I list only one port in a custom service, then it works.

    My question: Why can't I use a custom service with multiple ports in a NAT/firewall rule?

    Thanks.

    Len

  • I think I figured it out.  I had misinterpreted what source and destination meant when defining a service.

    Many thanks.

    Len