This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No Internet Access from WiFi connection

Hello,

I have recently purchased a Sophos XG Firewall and am in the process of configuring it. It is going to be used for Guest WiFi access and I am not able to ping the Comcast modem when I connect a laptop to the XG, therefore no Internet access. I have eased the Firewall rules and don't think this is the issue as I don't see blocks in the event logs. I think it has something to do with the Routing, NAT or GW config. Note: I can ping the Comcast modem from the XG diagnostic tools using eth1. If you have some ideas on what I may have not configured correctly, I would appreciate it.

Sophos GuestAP Wireless Network - 10.75.0.1
Sophos eth1    - 10.0.0.100(connected to the Comcast Modem) 
Comcast Modem   - 10.0.0.1

When I connect my WiFi laptop to the GuestAP, I can ping the GuestAP, and all of the eth

interfaces, including eth1 - 10.0.0.100. However, I can't ping the Comcast Modem - 10.0.0.1,


Settings:

Wireless Network:
Client Traffic - Separate Zone
IP Address - 10.75.0.1

Policy Routing:Status is Green
Interface - GuestAP
Source Network - Any
Destination Network - eth1
Services - Any
Gateway - eth1_GW


Gateway - eth1_GW :Status is Green
IP address - 10.0.0.1
Interface  - eth1
NAT Policy - MASQ
Source - LAN, WiFI, WAN, eth1

Gateway setup:
Source - LAN, WiFi, WAN
Destination - Any Zone, Any Host
What - Any Service
Action - Accept
Features - All selected

Firewall Rule:
Source - LAN, WiFi, WAN, eth1, 10.75.0.0/16
Destination - Any Zone, Any Host, Any Network 
What - Any Service
Action - Accept



This thread was automatically locked due to age.
Parents
  • Hi Dawgwood,

    Delete the Policy Route definition and edit the Firewall Rule to look like: 

    Source - LAN, WiFi, WAN, eth1, 10.75.0.0/16
    Destination - Any Zone, Any Host, Any Network 
    Identity: Unchecked
    Advanced > NAT & Routing > Select Rewrite source address (Masquerading)
    What - Any Service
    Action - Accept

    This should get you a working setup, you can refer to XG's how-to video more help in the configurations, refer the link in my signature below. 

    Thanks,

Reply
  • Hi Dawgwood,

    Delete the Policy Route definition and edit the Firewall Rule to look like: 

    Source - LAN, WiFi, WAN, eth1, 10.75.0.0/16
    Destination - Any Zone, Any Host, Any Network 
    Identity: Unchecked
    Advanced > NAT & Routing > Select Rewrite source address (Masquerading)
    What - Any Service
    Action - Accept

    This should get you a working setup, you can refer to XG's how-to video more help in the configurations, refer the link in my signature below. 

    Thanks,

Children