We have an issue on v18 where if we have HA enabled and the auxiliary device is on whether in active/passive or active/active connections to our DMZ network behind the firewall's fail. I spent 6 hours today on the phone with a Sophos tech reconfiguring the HA, looking over all the NAT rules, reconfiguring NAT and firewall rules, changing routing rules, just about everything was done. Thing is nothing worked. When the auxiliary device is on nothing can connect to the servers on the DMZ network, if I turn off the auxiliary device everything works! I can get to the DMZ network servers and there are no issues.
We really want to be able to have the 2 310 XG firewall's that we have to be in active/active mode and so I'm hoping someone on here has had better luck and maybe some pointers on what needs to be done.
My network setup
Internal LAN behind a L3 switch that routes internal traffic which then connects to the XG on Port 5.
DMZ is on a managed switch with no vlans on port 4
Both the XG's are connected to trunk ports on the switches as what the documentation for the HA shows.
I see the traffic going from Port 5 to Port 4 but then does not come back. At one point before everything done today and while it was being changed around I would be able to ping the DMZ servers but I could not reach their web sites.
TIA for any help
This thread was automatically locked due to age.