This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Guest Wifi with Sophos XG and Unifi APs

Hello, 

I hope someone can help me with this.

 

We currently have a LAN network with XG 135 and 2 Unifi controllers/switches with 10 Unifi APs connected.

We currently have LAN network (192.168.99.0/24) and WLAN configured with Unifi Controllers and APs, so devices can be connected to our corporate LAN network via ethernet or via wireless.

 

After that, I needed to create a separated WLAN (192.168.88.0/24) for guests, so noone in this GuestWifi can access any device in LAN network.

So, to get that, I created a new VLAN with ID 100 (Port1.100) in sophos in zone WIFI. I don´t know if this is the best way to separate the corporate lan and guest wireless lan. Let me know if I should set the Zone to LAN.

After that, I created the DHCP with the range 192.168.88.33 - 192.168.88.55

Then, in Hosts and services I created the group ip range 192.168.88.0/24

Then, I have configured the firewall rule to allow the traffic from Wifi to WAN.

After that, I have configured the new VLAN 100 in Unifi Controllers.

and a new wireless for the guess clients with this new VLAN.

After all this configuration, I can see the ssid new wireless from my wireless devices but when I try to connect it gets stuck in obtaining IP from DHCP which is provided by sophos XG passing through the Unifi controllers.

Can anyone help with this?

Thanks in advance.

Best regards



This thread was automatically locked due to age.
Parents
  • Hi,

    I expect you will need to change the zone type to LAN because wifi is only Sophos supported devices.

    Ian

  • G'Day Ian,

    Hope you find this mail in good health

    I'm having a similar setup, have plugged in Ubiquit AP directly to Port 4 on Sophos XG

    Have set i as LAN with IP 10.1.1.254 ( static )

    Also configured DHCP for this network as  10.1.1.10 to 10.1.1.15

    Is it necessary to create IP host and a firewall rule for this network

    At the moment im able to connect to Internet via this AP ,but on IP is been leased from Sophos DHCP

    Is it because i have not configured IP host and firewall rule

    Cos for my other wired networks namely Port 1 and Port 3 , i have not created any separate firewall other than the default ones which are created by Sophos during initial setup and those Clients seem to get IP from Sophos DHCP , so im bit confused whether firewall rule is necessary for this new wireless network im trying to setup

     

    Appreciate your cooperation as always

     

    Thanks


    Raj

  • Hi Raj,

    you will need to create a firewall rule for your new network range. The AP should obtain an address from your new IP lease range on that network.

    Ian

  • Hi Ian,

    Thanks for your email , have created a new VLAN on Port 4 ( the port where Ubiquiti AP is plugged in )

    Also created DHCP scope as below

    IP Host as below

     

    Firewall rule as below BUT NOT Enabled

    On Unifi Controller configured VLAN 40 as below

     

    Clients are able to connect to the new wireless SSID , also able to access Internet.

    My question was even without the firewall rule enabled , they are able to connect

    Also DHCP lease seems to work as expected

    Please advise on why the firewall rule is not taking effect

    Appreciate your assistance as always

    Thanks


    Raj

  • Hi Raj,

    Where does this rule sit in the list of rules, what is above it?

    Ian

  • Hi Ian,

    The firewall rule above it is 

    I guess since LAN is permitted to access WAN in this rule , the other firewall rule does not take any effect

    Please correct me if im wrong

    Appreciate your help

    Thanks


    Raj

  • Correct, it is a very open rule and does not offer much protection.

    Ian

  • Thanks Ian

    I understand having "any" option is a bad move

    Please advise for normal LAN network , with access to Internet, what would be a good config for firewall rule

    If you could share any screenshots, i would get a better understand, at the moment im just shooting in the dark

    Appreciate your cooperation

    Cheers


    Raj

Reply
  • Thanks Ian

    I understand having "any" option is a bad move

    Please advise for normal LAN network , with access to Internet, what would be a good config for firewall rule

    If you could share any screenshots, i would get a better understand, at the moment im just shooting in the dark

    Appreciate your cooperation

    Cheers


    Raj

Children