Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v18 SD-WAN policy routing in dual ISP WAN - doubling fw rules for what?

Hi all,

I'm writing after a v17 to v18 migration, I have read and watched Sophos videos and I'm starting to get an idea of the main changes in the traffic management rules BUT, I wanted to be sure that I'm not missing something in the "concept" and to avoid mistakes in all the NAT - Firewall Rules and migrated SD-WAN Policy routing that now I have to workout to clean all this mess that is bumped up after the upgrade.

Please keep in consideration that I'm in a Active-Passive XG330 cluster scenario with dual ISP WAN ports. The main use of the second ISP is only as backup so, switching traffic when the main traffic goes down, with a lot of exceptions that I don't mention here but that's the main use.

The routing order is

SD-WAN

VPN routes

STATIC

The first main question for me is ( please tell me if I'm wrong ):

Do I have to replicate every firewall rule in the SD-WAN policy routing, if I need to manage link failover in it? 

EXAMPLE: 

LAN to WAN - Access to internet only with specific port list and other options ( IPS,etc)  that I want to failover from ISP1 to ISP2

Thanks in advance,

Simo



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hey , Thanks for reaching out to Sophos Community.

    With v18 Firewall rules are decoupled from Gateway selection and NAT. Considering you've migrated configurations from v17.5 to v18, You'd be having the SD-WAN rules that are mapped to specific firewall rules (configured in v17.5). 

    You don't need to replicate each Firewall rule in the SD-WAN policy route. Since you only have two ISPs and the Primary ISP is serving all the traffic unless it goes down, You'll only need to add one SD-WAN Policy route, Define Source network, and the incoming Interface with Destination to ANY and select Active and Backup Gateways.

    Optionally, Since you've only 2 ISPs, You can change the gateway type to active or backup for the specific ISPs and don't make changes into SD-WAN Policy routes. Although this can become ambiguous if you decide to add a third ISP in the future :) 

Reply
  • FormerMember
    0 FormerMember

    Hey , Thanks for reaching out to Sophos Community.

    With v18 Firewall rules are decoupled from Gateway selection and NAT. Considering you've migrated configurations from v17.5 to v18, You'd be having the SD-WAN rules that are mapped to specific firewall rules (configured in v17.5). 

    You don't need to replicate each Firewall rule in the SD-WAN policy route. Since you only have two ISPs and the Primary ISP is serving all the traffic unless it goes down, You'll only need to add one SD-WAN Policy route, Define Source network, and the incoming Interface with Destination to ANY and select Active and Backup Gateways.

    Optionally, Since you've only 2 ISPs, You can change the gateway type to active or backup for the specific ISPs and don't make changes into SD-WAN Policy routes. Although this can become ambiguous if you decide to add a third ISP in the future :) 

Children