This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

8 Interfaces vs 4 w/ a switch

So I have a custom PC running now running XG and 4 interfaces seem to be working well initially at least

1 WAN

1st LAN (with a switch)

1 Wifi (AP100C)

2nd LAN (probably will just be for management)

 

I'd like to add a 2nd 4 port NIC (Intel, so is the current card) instead of using the switch as it is needed elsewhere.

 

I'm thinking that this would help me have a LAN for TVs, a LAN for PCs without communication between devices, and a LAN joined (bridged?) to a 2nd Wifi SSID LAN where people can temporarily connect to it to use an old network printer.

 

I am thinking that works pretty well for isolating devices\groups of devices and I wouldn't have to use VLANS. Any problems with this idea?  I have not dived into the firewall rules and IPS yet, honestly a little leary of it all. Just want to make sure this would work before buying a 2nd NIC.  Thanks

 

Also, my father has a three employee business (only him full time) and I would like to consider building a set of hardware for his office. Are there any economical routes for this size of business? Kind of hard to justify big subscriptions and don't want to go against Sophos's commercial policy. Thanks

 

Matt



This thread was automatically locked due to age.
  • Basically, you cannot work at the moment with VLAN on a Bridge. XG cannot Route between those VLANs. 

    But you can actually build a Bridge and assign individual zones to each Port.

    So you could build up a Layer 2 Bridge between those Ports and set up a Firewall rule "Zone printer can communicate to Zone Mobile".

    And thats across one layer 2 Bridge. 

     

    About XG Home:

    https://www.sophos.com/en-us/products/free-tools/sophos-xg-firewall-home-edition.aspx

    Its basically some free product for home usage (non commercial) 

    __________________________________________________________________________________________________________________

  • Actually it is running as a router and I would prefer that I have 8 physical eth ports with each going to it's own LAN aside from the WiFi and WAN of course.

     

    Sorry for it being unclear. I will edit it in the question.  My main concern I guess is will so LANs cause difficulties anywhere.

  • Hi,

    there will not be any difficulties. You do not appear to have many clients so your rule list will be quite small I expect.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.