Device: XG 125
Firmware:SFOS 18.0.5 MR-5-Build586
I am new to Sophos, so I apologize if this is a simple question (I hope that it is!) or one that's been asked 100 times before.
I'm trying to setup a guest network. My goal is two fold. One is to not allow access to our internal network. The second is to have different policies.
I created a Zone called Guest that only has ping and DNS as available services.
I setup a vlan (br0.2) with vlan id of 2 called GuestVLAN. The Zone is set to Guest.
I setup a DHCP server for that network using the IP of the GuestVLAN for the gateway.
I created a firewall rule. Source zone is Guest, destination is WAN. There is no web filtering or other security features enabled.
The firewall rule is linked to a NAT rule with SNAT set to MASQ.
I have my downstream switch connected to port 1. Port 5 on my switch is set to vlan 1 untagged, vlan 2 tagged. Port 1 on the switch is set to vlan 2 untagged.
What happens is weird. The laptop connected to port 1 on the switch (vlan 2 untagged) gets an IP in the Guest network IP range. I can ping outside sites (8.8.8.8 for instance) as well as resolve DNS names. But using a web browser generally doesn't work. Sites (like arstechnica.com) just timeout. I can ping those sites just fine. To further complicate things, sites do sometimes load. I tried rolling back to SFOS 18.0.4 and sites did load initially, but now they are not.
When I look at the Log Viewer, I see allowed rules to different IPs from that guest network, so it appears to be allowing things through. Though I do see some "Could not associate packet to any connection." entries, I see them for the internal network as well.
I'm just not sure how to troubleshoot this. The internal network is working fine.
And am I totally over thinking this? I know the APs can generate their own 'guest' network on the default VLAN. I'm just not sure how that can keep a guest out of the internal network.
This thread was automatically locked due to age.