This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG blocks everything in "bridged" mode

Hi,

 

I managed to install XG in "bridged" mode, but the firewall blocks all traffic between subnets.

 

My setup:

Native LAN: 192.168.10.0/24

HOME LAN (VLAN 101): 192.168.30.0/24

GUEST LAN (VLAN 105): 192.168.50.0/24

 

I have a bridged interface between port1(LAN) and port4 (LAN), and it's set up with ip 192.168.10.252

I'm able to manage the device from a web browser (if the client pc is in the Native LAN), but it's blocking all traffic between subnets:

 

Log comp: Invalid traffic

Action: Denied

Firewall rule: 0

Message: Could not associate packet to any connection

 

I don't have a firewall 0 when I go to the firewall section in the web interface. I have rule 1 which explicity allows ANY to ANY on any service or port.

 

 

The whole bridged mode is very undocumented IMHO. I've read the article here: https://community.sophos.com/kb/en-us/122973, but it doesn't address the problem I'm experiencing.

Port1 is connected to my main router (which passes both tagged and untagged traffic), Port4 is connected to my managed switch (the port it's connected to also passes all tagged and untagged traffic). I'm on the latest GA firmware.

 

Something else that bothers is me that I can't access the web interface from the Home VLAN, because a gateway cannot be defined when the bridge only consists of LAN ports. I can add a gateway if I add Port2 (WAN) to the bridge, but I'm not sure that's something I'm supposed to do. But this is not an urgent issue, I just want the traffic flow working for now.

 



This thread was automatically locked due to age.
Parents Reply Children
  • I never managed to solve it. The only way I got it working with multiple VLAN's is by using gateway mode.

    Despite what everyone tells you, you DO need to create a VLAN interface in all the subnets (which is not possible in bridged, at least when I used it).

     

    I've used it gateway mode for a while, but now I've given up and switched back to my Ubiquiti EdgeRouter, which seems to be a far superior product for my use-case. It might not have the same QoS or webfiltering, but at least it does routing and IpSec right...