This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing from WAN to LAN - Some help needed

Hello everybody,

I need some help here. I recently migrated from pfSense to Sophos XG home and I really like it, but I have some trouble getting my routing configured.

Basically I want to configure remote access to my media servers. What I did is: 

  1. Port forwarding from my provider's modem/router to Sophos (which worked before so that ok)

  2. Created a policy to allow the traffic

  3. Routed the traffic to the IP (in many different possibilities by now)

But its not working. In the logs I see denied traffic but its from a different source IP. 
I'm sure is a misconfiguration but I don't see where.



This thread was automatically locked due to age.
Parents Reply
  • Hello ,

     

    That is fine to have a private IP on the WAN interface. Your business rule is incorrect.

     

    1. Go to Host and Service > Service and add a service with source port "1:65535" and destination port "1994" "35665" " 35666" and "35661"
    2. Go to Firewall and create a business rule as following
      • Source Zone: WAN / LAN
      • Allowed Client Network: Any
      • Destination Port: #Port2-192.168.0.107 from the dropdown
      • Service: Select the above service
      • Protected Server: Server to which you want to forward your traffic
      • protected Zone: LAN
      • Change Destination Port: disable
      • Rewrite source address (Masquerading): disable, if not working enable it.

     

    Good Luck!!!

    Regards, Ronak.

     

     

     

Children
  • Hello Ronak,

    I tried that and changed a few other things as well, but its not working, so I'm giving up.

    I really appreciate your time and help, and the help of this awesome community! But I just don't have the time anymore to figure everything out. I wanted something easy to configure so i can continue with my other tasks (my LPIC exams) but apparently my Firewall knowledge is to limited.
    In my professional life I mainly use Fortinet and Barracuda, so its probably best for me to stick with these brands for now until I gather more time and knowledge to dive into a new platform.

    Thanks again,
    Jimmy