This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't connect to the Internet

Hello Team,

I'm currently using Sohpos xg 230 but lately it has been really slow. This is how the network to designed, I have 2 ISP's(First WAN IP 41.x.x.29/30 & 105.x.x.24/30) terminating on the Sohpos on PortA2 and A5 while using PortA4 as my LAN Port. The interesting part is traffic originating from LAN "Ping" can reach the Sohpos WAN IP (41.x.x.30/30 & 105.x.x.25/30) but can't reach the ISP Gateway which is 41.x.x.29 & 105.x.x.24. 

Please assist



This thread was automatically locked due to age.
Parents
  • Hello Adam,

    Thank you for contacting the Sophos Community!

    Do you have valid firewall rules for the traffic? Are the Local ACL allowing PING?  Does the Live log says anything when you try to Ping 8.8.8.8

    If you SSH to the XG and source a Ping from one of the WAN interfaces, are you able to have a reply packet? 

    Once you SSH please press 5>4 to end up in the console>

    From here type 

    console> ping interface Port2 8.8.8.8

    console> ping interface Port5 8.8.8.8

    Do you see a reply?

    If you do see one, most likely you might be missing a Firewall. 

    If you do 

    console> drop-packet-capture 'x.x.x.x' (Substiture the x.x.x.x for a computer IP)

    Do you see any packets being dropped? if so please copy and paste the output

    Are you running v17 or v18?

    Regards,

    • Yea, actually we've alot of access policies ranging from cateconnectigory based policies, bandwidth allocation policies e.t.c though i can still have access to the Web GUI and ssh to the CLI. but when i ping from the LAN to i can access all my local devices Sohpos included.

    So i was think since i can ping my Sohpos WAN IP connecting me ISP Gateway then is possible that my firewall is denying returning traffic.

    But right now as it's i can't really say what exactly is going, if anything, I'm sure something is going on with my firewall

  • Hello Adam,

    The XG is a Stateful firewall, so it won't deny return packet if there is matching rule.

    I would recommend you to create a Firewall rule on Top of the rest of the Firewall rules without any restriction and see if it works, also try what I mentioned above.

    Regards,

  • Thanks for sharing this Emmanuel..

    Another thing is that at some point I couldn't access the |Web GUI so i had to enable that from the terminal though I'm not sure exactly why that happened. below is the command i used.

    #system appliance-access enable

    what do you think?

    Regards,

  • Thanks for sharing this Emmanuel..

    Another thing is that at some point I couldn't access the |Web GUI so i had to enable that from the terminal though I'm not sure exactly why that happened. below is the command i used.

    #system appliance-access enable

    what do you think?

    Regards,

Reply
  • Thanks for sharing this Emmanuel..

    Another thing is that at some point I couldn't access the |Web GUI so i had to enable that from the terminal though I'm not sure exactly why that happened. below is the command i used.

    #system appliance-access enable

    what do you think?

    Regards,

Children