This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't get to DMZ servers when internet goes down

We have a DMZ subnet off of our XG 550.  When our internet connection goes down, internal clients cannot get to the web servers located on that DMZ. If you do a tracert, it is attempting to send the traffic out the other internet connection and get to the webservers from outside for some reason. 

Any suggestions for this?  We have no static route to the DMZ on the XG since the internal clients should be able to get to that direct attached subnet.  I have a second internet connection so I can force my traffic out the secondary and replicate this issue at will.  I have a ticket open with Sophos support and they are investigating as well but I figured I would throw it out on the forum and see if a routing expert has any ideas on it.  Thank you all!



This thread was automatically locked due to age.
Parents Reply
  • Hi Josh,

    does the traffic to the DMZ need to go to the internet, you could setup an FQDN in the XG using the internal address of the server, do not tick advertise on WAN and create a rule to allow the traffic between the subnets.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data