This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Public IP block routing through single WAN IP

Installed Comcast Metro E fiber Internet connection.  Was unable to use Sophos UTM as I could not turn up an IPSec point to point tunnel on an additional IP.

Sophos recommended installing XG firmware on the SG230 firewall as it will allow tunnels on additional IPs.

I am at a loss how to set up the configuration per Comcast recommendation here. 



This thread was automatically locked due to age.
Parents
  • Hello ,

    As per my understanding from the diagram, I would see that there is one connection to Comcast network from the customer's premise. I would like to know do you plan to connect to a different router at the same time or active failover type of connection?

    The WAN is not direct public facing and is NATTED to a private address so you would need to initiate the connection from Customer's premise.

  • I actually have two SG 230 firewalls in Active/Passive configuration under UTM.

    I broke the HA and converted one of them to XG and am attempting to build what Comcast shows.

    The Sophos box needs to route the 5 assigned public IPs through the point to point single IP.

    When I re enable HA there will be a dumb switch between the two firewalls and the single port on the Ciena device.

    I just don't see how to do this.

Reply
  • I actually have two SG 230 firewalls in Active/Passive configuration under UTM.

    I broke the HA and converted one of them to XG and am attempting to build what Comcast shows.

    The Sophos box needs to route the 5 assigned public IPs through the point to point single IP.

    When I re enable HA there will be a dumb switch between the two firewalls and the single port on the Ciena device.

    I just don't see how to do this.

Children