This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

BGP and multiple AS?

Hi,

 

I'm currently using an Ubiquiti EdgeRouter at home, and I'm evaluating Sophos XG, to check if it's a suitable replacement, as the firewall capabilities of EdgeRouter are limited.

 

One thing that struck me, is that I can only define one AS on the BGP page in the Sophos XG UI. UBNT supports multiple AS's, each with it's own configuration.

 

Am I missing something here? It seems weird that Sophos XG doesn't even match the EdgeRouter in routing functionality, despite the price difference.



This thread was automatically locked due to age.
Parents Reply Children
  • Ah, this makes sense. If I understand correctly this won't be an issue in my case, as routing happens on the EdgeRouter.

     

    One more question: If I put the XG in bridged mode, between my router and my managed switch, how would I create different fw rules per VLAN (example: allow VLAN 100 to access the internet, but not VLAN 200)? Zones are tied to an interface if I'm not mistaken, so you can't use that in bridge mode. 

  • You are right, you cannot use the Zone Basis in this case. But you can use Zone ANY and still specify with network objects everything.

    You are not forced to use the Zone concept. 

    __________________________________________________________________________________________________________________

  • Probably a stupid question, but how could I create a network object that indicates "the internet"? :-)

     

    It's easy for my own VLAN's and corresponding IP ranges (VLAN 100 is 192.168.30.0/24, for example), but I cannot create subnet groups for all public IP ranges out there :-D

  • It is called any.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.