Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Schedules in Routing

Hi,  This is my first time asking a question, so please bear with me.

Sophos obsoleted my XG 105 which is running 17.5.  So I bought an XGS 107 now running 18.5.

In 17.5 you could specify a firewall rule to take affect at scheduled times.  My set up looked like:

LAN1: Internal

WAN2: HughesNet Residential (02:00-08:00 50GB Bonus Bytes, 15GB Anytime per month)

WAN3: HughesNet Business (08:00-18:00 30GB Bonus Bytes, 10GB Anytime per month)

So individual firewall rules would take affect at different times of the day and different days of the week (for 18:00-02:00).  This was all good because the NAT and Routing were part of the Firewall rules.

On 18.5 the NAT and Routing are separate.  The Firewall rule can still link to a NAT, but the Firewall can't link to a Route.  If you migrate from 17.5 to 18.0, Routing links are created, but I can't migrate the XG 105 past 17.5, so I am hand entering all the rules because another WAN was just added:

WAN4: SpaceX Starlink (5.5 minutes Bonus Bytes (unlimited), then 30 seconds nothing; cycle repeats every 94 minute orbit; this will get better, but when they put on the data cap, it will be like a third HughesNet, just lower latency)

I can't figure out a way to create a link from a Firewall rule to a Route.  I don't think this is the long term clean way of doing things.  Since Routing doesn't include a Schedule, I can't schedule the Route.  There are a lot of reasons to send data to each different satellite (also via a port Alias), or to get the status from each satellites' modem (or PoE brick).  I tried marking each packet in Firewall with DSCP, to see if the Routing could identify it, but that didn't work.  All WANs are either Active or a Backup at different times of the day.

Was this functionality purposely removed?  What am I missing?



This thread was automatically locked due to age.
Parents
  • Routers sometimes are in need of reboots to keep them running properly. One thing to check if your are doing this daily is your channel settings. Try a different one. Perhaps you have something in common with something nearby. Maybe moving the router to a different spot will help as you may be near something it doesn't like.

    Outside of this a timer plugged into the wall, or a built in timer on a schedule is not a bad idea at all if it does not interfere with anything.

    --Edit uPnP is fine to be enabled if you have devices or other things on your network that need access. It will automatically configure the ports for for and make things discoverable. I like it when my cloud drives show up in my tv automatically. yay. Unless by enabling uPnp you allowed access to an exploitable device on your network, I would say you are safe with leaving that on.

    MyBalanceNow

Reply
  • Routers sometimes are in need of reboots to keep them running properly. One thing to check if your are doing this daily is your channel settings. Try a different one. Perhaps you have something in common with something nearby. Maybe moving the router to a different spot will help as you may be near something it doesn't like.

    Outside of this a timer plugged into the wall, or a built in timer on a schedule is not a bad idea at all if it does not interfere with anything.

    --Edit uPnP is fine to be enabled if you have devices or other things on your network that need access. It will automatically configure the ports for for and make things discoverable. I like it when my cloud drives show up in my tv automatically. yay. Unless by enabling uPnp you allowed access to an exploitable device on your network, I would say you are safe with leaving that on.

    MyBalanceNow

Children
No Data