This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VLANs on single LAN interface

Hello everybody and thank you for your support

I'm deploing a new couple of XG Firewals instead of two old UTM9 but i've found many problems on VLAN configuration.

This is my actual UTM9 configuration:

As you can see i've the ETH1 configured with 3 Vlans and everything works fine.

 

On the XG i'm trying to replicate my configuration creating 3 vlans on eth8 

My first question is: why do i have to configure an ip on the physical ifc if i'm configuring vlans on that interface?

And why the only working vlan is the one on the same subnet of the physical interface?

 

If i connect something on 172.16.100.X subnet everything works fine, but on 172.16.90.X don't work.

The only firewall rule i've created is from (zone) LAN (host) VLAN100 network; VLAN90 network ---> WAN

My network topology is very easy, just 2 FW and 2 managed switch. 

On the switches the port connected to the XG is configured in trunk mode.

 

 

I  have to use only one cable between XG and Switches as is

The XG version is SFOS 17.0.6 MR-6



This thread was automatically locked due to age.
  • Hi Marco,

     

    Were you able to resolve this, i have similar issue. Port 1 on Sophos XG (172.16.16.254 ) and Port1.200 ( 10.10.200.254 ) as VLAN 200

    Port 1 connected to Cisco switch fa0/1

    How can i enable other ports on the cisco switch so that they are on VLAN 200

    Appreciate any assistance

  • Hi LuCar,

     

    i have port 1 from sophos xg firewall which also has vlan 200 identified as Port1.200 ( on Sophos XG) 

    Now Port 1 is connected to fa0/1 on cisco 3560. 

     My query is , how can i assign vlan 200 to other ports on the switch , so that when a device is connected to say for example fa0/5 it gets an ip from VLAN 200 ( 10.10.200.50 to 10.10.200.150 range , DHCP enabled in Sophos XG ) 

     Appreciate any assistance 

  • Hi Marco,

     

    I got this setup working on my end, please let know if you need a hand

     

    cheers

    Raj