This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Lutron Caseta and Apple home/Siri issues after installation of Sophos home

Hello,

I recently configured a Sophos XG home device for use and it has been working great, except for one issue (so far):

Siri doesn't seem to work correctly with our at home setup. We have a Lutron Caseta smart lighting system throughout the home, that device is plugged into a switch into Port 1. Port 3 is bridged to LAN which is our Sophos AP 55c. I do have 'Enable routing on this bridge pair' enabled.

My Wireless devices Apple Home Pod/iPhones/Apple Watch/MacBook/etc. are having difficulty communicating with the Lutron Caseta. Normally. I should be able to say "Hey Siri, turn on the kitchen lights" and it's done pretty instantly. However, intermittently, this works and doesn't work since I got the Sophos XG configured. Meaning, Siri responds "cannot communicate with devices"

I am able to access the Lutron Caseta at all times (even when Siri is not working) with the Lutron app. When I check the Apple home app (which I should be able to control all the lights with on my phone) during Siri not working, the buttons all say "Updating" and I cannot access the light switches.

That being said, I have a LAN > LAN rule configured with Any / Any using any services. Would it be wiser to configure a Lan > Lan Port 1 / Port 3?

Additionally, I did a packet capture & checked the firewall logs between the Lutron device and my iPhone using Siri and saw the following

I did some research and am aware that Invalid_traffic with no header seems to be dropped and this is normal for logging, however, when i've taken packet captures and Siri is working, I don't see any invalid_packet drops.

What other troubleshooting can I do? Does anyone else have issues with at home apple devices? Is there something additional I need to configure? Any assistance is greatly appreciated, the Sophos community is great and I thank you for any help.

 

Some additional information:

Firmware version: SFOS 17.1.2 MR-2

I have IPS enabled, Country blocking, and HTTP Malware scanning (not configured HTTPS, yet) but that's to WAN (Screen shot of firewall rules below)

Also, if you guys catch anything maybe I didn't setup (I regard myself as novice > intermediate with networking) please let me know.



This thread was automatically locked due to age.
  • Hi,

    you have to many rules with all services allowed. You do not rule 11, any of the applications you have with that rule will initiate the traffic so that will come in via the outgoing rule.

    I need to study your rules in more detail to see what else I can assist with.

    Ian

  • Thank you. i've disabled rule 11.

    I appreciate any advice in configuring the services

  • 'Enable routing on this bridge pair' >> If you have this enabled, it means that the bridge will in participate in routing else traffic will be forwarded based on MAC learning. Depending on how Siri's Home kit works; it may need your devices to be on the same broadcast domain (so no routing).  Try turning off the routing on the bridge and report back.

    P.S - You can turn off the invalid traffic loggging in the System Services >> Log Settings.

  • Hi,

    I am not sure why you have a default rule that allows all traffic out, really defeats the purpose of the rules above it?

    You appear to be trying to limit your kids access to the internet, but you allow all traffic from their devices and if they have figured out how to change the IP address of their devices the traffic will go out the default rule at the bottom.

    What exactly are you trying to achieve with your rules?

    Ian

  • rfcat_vk said:

    Hi,

    I am not sure why you have a default rule that allows all traffic out, really defeats the purpose of the rules above it?

    You appear to be trying to limit your kids access to the internet, but you allow all traffic from their devices and if they have figured out how to change the IP address of their devices the traffic will go out the default rule at the bottom.

    What exactly are you trying to achieve with your rules?

    Ian

     

    Hi RFKat, I have MAC address filtering enabled on the kids devices. What do you suggest I do to limit as such?

  • AB5g said:

    'Enable routing on this bridge pair' >> If you have this enabled, it means that the bridge will in participate in routing else traffic will be forwarded based on MAC learning. Depending on how Siri's Home kit works; it may need your devices to be on the same broadcast domain (so no routing).  Try turning off the routing on the bridge and report back.

    P.S - You can turn off the invalid traffic loggging in the System Services >> Log Settings.

     

     

    Hi AB, I disabled routing as suggested, but the problem still intermittently occurs.

  • I've found that HTTP scanning causes issues with some of my devices. Creating a rule which excludes the Apple Home and any other smart devices may help

  • kieran90 said:

    I've found that HTTP scanning causes issues with some of my devices. Creating a rule which excludes the Apple Home and any other smart devices may help

     

     

    Thanks, i'll try this now. I had disabled HTTP scanning for testing purposes but it didn't seem to help. I'll report back

  • rfcat_vk said:

    Hi,

    I am not sure why you have a default rule that allows all traffic out, really defeats the purpose of the rules above it?

    You appear to be trying to limit your kids access to the internet, but you allow all traffic from their devices and if they have figured out how to change the IP address of their devices the traffic will go out the default rule at the bottom.

    What exactly are you trying to achieve with your rules?

    Ian

     

    The default rule created was allowing all traffic out, i've restricted it just to the internet LAN subnet. I'm going to start tweaking this a bit, but I guess I don't have the greatest understanding the configuration as I have it set up. I am trying to learn it. Any help would be appreciated, or suggestions. I generally learn through doing in real time best.

    thank you for taking the time to respond

  • " I have MAC address filtering enabled on the kids devices. What do you suggest I do to limit as such?"

    Hi,

    I am not sure what you mean as I was not aware that feature had been added to the XG yet.? I know it is in the feature request list.

    Ian