Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

cannot route between 2 subnets on 2 different interfaces and same physical lan - RULE ID 0 - VIOLATION FIREWALL

xg106
- port 1 - lan 1 - 172.16.16.16 / 255.255.255.0
- port 2 - wan
- port 3 - disconnected
- port 4 - lan 2 - 192.168.123.65 / 255.255.252.0 gateway 192.168.123.3 (xg106)

- PC1 (LAN 1) - 172.16.16.200 / 255.255.255.0 gateway 172.16.16.16
- PC2 (LAN 2) - 192.168.123.89 / 255.255.252.0 gateway 192.168.123.3

xg106 can ping 192.168.123.89
PC1 cannot ping 192.168.123.89

xg106 interfaces

lan2lan rules added

PC2

PC1

PACKET CAPTURE



This thread was automatically locked due to age.
Parents Reply
  • FormerMember
    0 FormerMember in reply to peterson

    Hello ,

    #Port1 and #Port4 only include an IP address configured on the interface.

    You need to put the entire network under source/destination networks of rule ID #6 and #7.

    You may also merge these 2 rules and can configure just one as shown below.

    192.168.120.0/22 includes 192.168.120.0 - 192.168.123.255 address range.

Children
No Data