I have to be honest and state that the Sophos UTM OS is much more intuitive than SFOS. I can't think of a single configuration that's easier to setup on SFOS vs UTM.
Anyways, I have the built-in Wifi AP on a XG125w configured as follows:
- Using default "Sophos" wireless network, which is configured for the "LAN" zone by default
- "Bridge to AP LAN" mode
- Client isolation is disabled
- Wireless protection is enabled in the wireless global settings
- Allowed zone is set to LAN and WiFi in the wireless global settings
I also have a LAN to LAN firewall rule configured, to allow connections between any source and any destination for any service. Since the global wireless settings "allowed zone" includes the LAN zone, I presume this should be enough to allow a Wifi client on the 10.0.6.0/24 subnet to access an IP printer on the LAN (192.168.0.0/24). My understanding with the SFOS 17.0.5 MR-5 firmware is that I don't need to manually bridge the Wifi interface to the LAN. I did notice that under the AP settings -> Advanced section there is a slider labeled "Bridge to Ethernet" but presumably this isn't needed for "Bridge to AP LAN" mode? Documentation is unclear.
Unfortunately, I'm doing this configuration remotely so I'm not able to directly test connectivity from the Wifi network to the printers.
Have I overlooked anything to get this to work? Is it necessary to setup static routing between the 10.0.6.0/24 and 192.168.0.0/24 subnets?
This thread was automatically locked due to age.