This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAN Link Failover - customer in the same subnet

Hey!

So, I'm fairly new to Sophos and I'm still learning the specifics. We have a bit of an annoying problem.

We're using a dynamic IP VDSL connection as our failover link (port3) together with our main connection (port2). We do some small time hosting for our closest customers and everything is working very well. But one of our customers recently got a WAN IP that is in the same subnet as our failover link. Say we have 90.200.200.X and so do they.

The problem is that our Sophos XG 210 tries to send all the traffic from this customer back out through the failover link. So when I ping from them to us, I see traffic coming in on port2 and leaving on port3, which obviously doesn't work. Shouldn't this gateway be completely disabled unless the main connection goes down?

The failover is setup with standard failover settings according to https://community.sophos.com/kb/en-us/123530

Firmware is 17.1.3 MR-3

 

Dunno if more information might be required, but I'd appreciate the help :) Thanks!



This thread was automatically locked due to age.
Parents
  • Sorry that I'm bringing up such an old post again, but I figure hey that's okay since it seemed to go unresolved.

     

    Daniel, not sure if you still have the same configuration but, what settings do you have on your firewall rules? You can pick specifically which gateway to send traffic out from for primary, and secondary, or pick none etc.

Reply
  • Sorry that I'm bringing up such an old post again, but I figure hey that's okay since it seemed to go unresolved.

     

    Daniel, not sure if you still have the same configuration but, what settings do you have on your firewall rules? You can pick specifically which gateway to send traffic out from for primary, and secondary, or pick none etc.

Children
No Data