This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall policies LAN->DMZ never work

Hello,
Company im working in own brand new Sophos XG-125 (latest firmware)

After initial configuration and tests everything is ok (with internet connection and LAN) but when I try to create Firewall policy Lan/any/any -> DMZ/any/any it does not work. (10.10.10.x -> 212.182.x.x)

I tried setting up everything default and turning off (and on...) every single service like malware scanners, filtering, traffic shaping etc.

We have few servers in our internal network that can not communicate to outside world.

Another problem is when i try to SSH to some servers after initial connection when i type user, server is taking AGES to respond and ask for password.

When I switch back to old Fortigate everything is working great again, i even resetted fortigate and configured it again -> works flawless, SSH responds in blink time.

Firewall policies does not work AT ALL for me, no matter what kind of rule I create it is useless. (it says its "on")

Am i doing something terribly wrong or have I missed some crucial setting?



This thread was automatically locked due to age.
Parents
  • Agreed about the firewall rule picture, without it its pure speculation.

     

    But since we are guessing.

    Based on the information given, this rule does not need to be MASQed, though selecting the wrong one, could be a problem.

     

    I place my bet on that "Match Known User" checkbox is checked. This would stop traffic if you are not using this user feature.

Reply
  • Agreed about the firewall rule picture, without it its pure speculation.

     

    But since we are guessing.

    Based on the information given, this rule does not need to be MASQed, though selecting the wrong one, could be a problem.

     

    I place my bet on that "Match Known User" checkbox is checked. This would stop traffic if you are not using this user feature.

Children
No Data