This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG135 on initial set up removed bridge mode and configured port will not allow internet

Hi

We have recently converted from WatchGuard to Sophos and still trying to find our way around so any input would be appreciated.

Currently we have 2 issues but one I believe is to do with web filtering so will post appropriately. The main issue is we have a new XG135 which came set up by default in bridge mode.

the bridge was removed, new zones were created for Guest, Phones and Management, port 1 was set up for management, port 2 for WAN, port 4 for LAN, port 5 for Phone system and port 6 for Guests with a VLAN id of 20. DHCP was created for Phones and Guests. Firewall rules were then created for the LAN,Phones and Guests to access the internet.

The rules were identical but for some reason the Guest port is not allowing WAN/internet access and I can't see why, I feel I may have overlooked something simple but having looked several times am lost at what to look at next.

Basically we have a wireless AP connected to a switch untagged for LAN ssid and tagged ID 20 for Guest ssid, we have another port tagged id 20 which is connected directly to Port 6 on the XG unit which has the VLAN id of 20.

Users connecting to the LAN ssid get internet and LAN access however the Guest users receive the relevant ip information from the DHCP configured for Guest network but don't have any internet access.

We have used the port interface as the gateway as we have for the other ports but just don't get why this port doesn't work and the others do.

if there is any other info I could provide which may help with input please ask



This thread was automatically locked due to age.
Parents Reply
  • Hi

    Using a TP Link AP set up with 2 SSID's, lan and guest which are VLan over single connection. this connects to Dell 2000 series switch which is Tagged for VLan 20 and default lan Untagged.

    the lan segment works fine, the guest segment receives IP info (which appears correct) from guest port on firewall and cannot access the internet. Suspect DNS?

    Diagram attached.

    Thank you

    3833.network diag.pdf

Children
No Data