Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 17.5.14-1 and RED 60 - No Traffic from Branch 2 Head Office

Hi,

i have a RED60 device and followed the Sophos documentation and several YouTube Videos for a Basic Setup.

Like this from sophos support: Sophos XG Firewall (v17): Adding a RED Device

I had a Basic Setup with a RED Device in Standard/Unified Mode and added 2 Firewall Rules like in this Video.

Local LAN is 192.168.0.0/24 and Sophos XG has 192.168.0.254

RED Setup

And two Firewall rules

 From a Branch Office PC i can ping the internal IP of the XG (192.168.0.254).

But i can´t ping intern Server like 192.168.0.194 (Gateway for all internal Servers is 192.168.0.254)

And i can´t browse the Internet.

Red Device is behind a LANCOM Router and is connected to Sophos XG 

Where is my error?

Can someone help for this Basic Setup?

Thanks

Jürgen



This thread was automatically locked due to age.
Parents
  • FormerMember
    +1 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    The first step to troubleshoot issues related to the traffic is to take a packet capture on the firewall. With packet capture, you could find out if the traffic is dropped or forwarded by the firewall. 

    Is ICMP allowed on your internal servers?

    Could you please try to add the RED network to the source network instead of the interface #reds1? 

    Check out the following KBA for more info: Sophos XG Firewall: How to monitor traffic using packet capture utility in the GUI.

    Please provide the screenshot of the packet capture. 

    Thanks,

  • Thanks,

    Servers are all reachable with ICMP, i had LANCOM Router with IKEv1 attached and all that stuff.
    All worked.

    But i think i see what you mean, if i Change the Firewall and hover above the #reds1 i see this Network.

    This is the DHCP range from LANCOM to RED60 ...

    I will define a Branch Network with the 192.168.10.0/24 Range as a new Network and add this to the Firewall rules.

    Thanks

Reply
  • Thanks,

    Servers are all reachable with ICMP, i had LANCOM Router with IKEv1 attached and all that stuff.
    All worked.

    But i think i see what you mean, if i Change the Firewall and hover above the #reds1 i see this Network.

    This is the DHCP range from LANCOM to RED60 ...

    I will define a Branch Network with the 192.168.10.0/24 Range as a new Network and add this to the Firewall rules.

    Thanks

Children