Hi,
I've playing around during the last few days with Sophos XG at home, but I can't seem to make it work the way I want and need. I have a Juniper SRX210 doing all the routing and layer3 filtering, and I want to integrate the XG transparently in bridge mode to be able to sniff all the traffic and see what I can do with it.
My current setup is as follows:
firewall/router SRX210 HE
switch T1700G-28TQ
server ESXi 6.0
My SRX is ingesting a public IP from a VM router in modem mode, and for this is using a different VLAN which is connected to the switch and ingested via a LACP between the SRX and the switch. I also have an LAG between the ESXi and the switch, which host the VLANs below (replicated in the SRX)
In addition to this I have SSIDs, one home standard and the other with admin permissions over the network, each one on a single VLAN. I do want to test this integration with the latest admin SSID, to not disturb my missus, which will cause me headache as she won't reach Instagram.
So, let's focus on the matter. As the XG installation requires two or more interfaces to work, I've created two VLANs, IPS_External and IPS_Internal, which will then be obviously on the SRX and with different network addressing.
As of now, I've tested the XG installation with both interfaces on the same VLAN (IPS_External), but when I turn it into bridge, my whole network stops behaving, and buy the looks of it I DDoS my SRX somehow, which I suspect is an ARP flooding meaning the same IP with different MAC addresses through the same port/trunk, or even a Spanning Tree problem (I've no idea whether the XG has STP by default).
I really like the looks of XG and the guys from Abingdon are doing a great work, though have lot of stuff to refine. The above said, I have several questions that I hope the community or even some staff from Sophos is able to help me with:
- I wonder how this bridge capability works and which MAC address of the two you merge, the XG uses once in bridge mode?
- what is likely to be causing me problems once I setup bridge mode?
- how the XG will behave regarding layer2/3 if I setup each interface on different VLANs (IPS_Internal & IPS_External) and fusion them into a bridge one?
The web/ftp/dns traffic forwarding through the XG is a different matter and it's out of the scope of my main problem.
I hope all the above makes sense to someone :)
Many Thanks in advance,
Alberto.
This thread was automatically locked due to age.