Sophos XG 18.0.5 (MR5).
Currently a /30 is assigned as the primary WAN subnet on PortB.
Q1: When adding a subnet to a port, it does not seem possible to pick individual adresses in a FW or NAT rule. I assume NAT and FW are "port based" and not "IP based". Correct?
Q2: In order to be able to use individual adresses in NAT/FW rules we have added 16 adresses from a /28 to PortB, so I can pick and choose per IP when making NAT and FW rules.
Is there any way I could just have added the /28 subnet and achieved the same?
I'm no FW expert, so if I'm completely off-tracked and this approach is "stupid" let me know :-)
Q3: There are currently some IPSec connections configured to use PortB (= Default GW IP) as local gateway.
Due to setup of a redundant connection, we need to change this network to a new /29 subnet.
I am planning to change one IPSec connection at a time, using one of the IP addresses from the /29 subnet (#PortB:xx) instead of the GW (#PortB). This way we can do a slow transfer instead of having all our remote partners doing the change when the WAN IP changes.
Are there any pitfalls using the XG and #Port:xx for the local gateway for IPSec connections?
Thank you for any input!
/JP
This thread was automatically locked due to age.