This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing Not Working

Hello Everyone,

     I inherited a Sophos XG firewall from my predecessor, I've never touched one of these before.  I am trying to get traffic to be routed from port 1 (192.168.2.1) to port 4 (192.168.3.1).  Both ports are in different zones but are specified as LAN type zones with all services but telnet turned on.  I am trying to get traffic from endpoints on port 1 to flow to a couple of servers on port 4.  I have read through several different forum posts etc... and everyone says the same thing.  Create a firewall rule for both directions of the traffic and put it at the top of the list.  I have done this and it doesn't work, I can see the traffic in the logs but its being matched to the catchall LAN->WAN rule at the bottom of the list and being routed uselessly out the WAN interface (Port 2).  I also don't see all the traffic in the logs, for example, pings from my computer to the server on the other side time out and I never see those logged.  I have also tried putting both interfaces in the same zone (LAN) and changing the rules accordingly but it still doesn't work.  I've been at this for hours and I can't find any reason why this isn't working.  Thank you.



This thread was automatically locked due to age.
Parents
  • Ok so I managed to figure out some parts of it.  Appearantly on the rule you have to uncheck the match users, even though it said allow all users.  After I did that traffic was able to flow and I can ping, but despite this the audio on the phones is not working, its like there is a firewall rule but the rules i put in have not nat and allow everything between those subnets...

Reply
  • Ok so I managed to figure out some parts of it.  Appearantly on the rule you have to uncheck the match users, even though it said allow all users.  After I did that traffic was able to flow and I can ping, but despite this the audio on the phones is not working, its like there is a firewall rule but the rules i put in have not nat and allow everything between those subnets...

Children
  • Nevermind, i've decided I have hit a point of diminishing returns and we'll have to go through and configure each of the phones by hand and do things right after we rip out all the Sophos firewalls across every location. 

    I mean no disrespect to anyone who uses these things, but these have got to be one of the worst firewalls i have ever used.  It constantly locks up and the user interface is very counter-intuitive.  The rules make no sense either and the zones randomly don't work, I will never ever buy, recommend, or use one of these things...ever...at the very least it will preserver my sanity for just a little longer.