Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I am unable to get internet access on my Cisco WAP371 connected to my XG firewall.



I have a Sophos XG firewall paired with a number of Cisoc WAP371 access points. The access points can be reached and configured on network, but connecting to the SSID does not allow an internet connection. Please help! I have DNS set to my domain controllers. 


Thank You, 



This thread was automatically locked due to age.
  • Hi Corey,

    when your users connect to the APs do they get an IP address? Are the IP addresses assigned to the AP users allowed out of the XG with a firewall rule?


    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, 


    I do get a valid IP when connecting to the SSID. I am able to access devices on the LAN just not the internet. IPCONFIG reveals that the DNS servers are not resolving. What sort or rule would I need to create?  I have 5 WAP's setup with static IP's connecting to a POE switch which is connected to my LAN port on the Sophos Firewall. The LAN ports are all bridged with a Lan - Lan firewall rule. There is also a Lan-Wan firewall rule to allow traffic out to the web ( default rule with Sophos XG ). All other devices on the LAN are able to connect to the internet. DHCP and DNS are handled by my domain controllers. Thanks for the help! 

  • Additionally, I am able to see my IP lease in DHCP for my computer connecting to the SSID. If I go into the properties of the WiFi adapter and change the DNS entry to manual I can set the DNS servers and internet access is restored. The odd thing is that this was all working before I switched over to the Sophos firewall. 


    LAN, Any Host --> LAN, Any Host

    LAN, Any Host --> WAN, Any Host


  • Do wifi connected users stays under LAN zone or are there another zone?

    Eren ERTAS


  • WiFi users stay under the LAN zone and are assigned an IP address from the same subnet. I am not using the Firewall to manage the AP's. I do have them clustered through the Cisco software. 

  • Ah this is fine, i'd worked cisco controller software before. The odd thing is i needed to add dns servers to controller software to make it work on my latest deployment. But you can still write your domain servers to dns on cisco. I think its not about Sophos.

    Eren ERTAS