Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAN to LAN Policy not working, not able to ping from port 3 to port4 and ViceVersa.

I have Sophos XG firewall, already created LAN to LAN Policy.

In Port 2 : WAN

   Port 3 : LAN : 10.0.0.0

   Port 4: LAN 192.168.0.0

   Port 5: WAN : WAN

I am not able to ping from 192.168.0.0 network to 10.0.0.0 network . However I can ping the gateway 192.168.0.1 from both the network.

Need help in this regard.



This thread was automatically locked due to age.
Parents
  • Hi ,

    1. Move your LAN2LAN rule to the top of the Firewall rules (Drag & Drop)

    2. Ensure that you didnt specify a specific network in the Source LAN or Destination LAN.  Otherwise the ping is possible only one way, and you will require a second LAN2LAN stipulating that the same ping attempt initiated from the other LAN will have access to do so as well.

    In the above image, i have LAN2LAN in a Firewall Group called "LAN2LAN" as well, just keeps rules organized, but try setting it as you see here.

  • As per your suggestion I have created both LAn 2 LAn group and firewall rule, but still able to get ping from one port to another. Screenshot attached.

  • Hey Subhash, thanks for the screenshot. Could you post a snapshot of your Interfaces as well, just block out any WAN information from view.

    Also, if you go to Administration > Device Access, is "Ping/Ping6" checked off in LAN zone?

  • Please find the attachments. Ping/Ping6 is also enabled in LAN Zone.Interface

    Ping on LAN

  • Subhash, did you ping from machines that received DHCP addresses, or were they statically assigned, and were the correct gateways received?  The /16 subnet on Port4, is the same mask on the client your are pinging from?

    Are Port 3 and 4 separated by two separate switches, or same switch with two separate Untagged VLANs in Access mode?

  • I have tested pinging from both machine with DHCP assigned IP and Static Assigned IP.  Gateway 192.168.0.1 is accessible form both port 3 and port 4. Yes client is also having the same subnet 255.255.0.0 as it provides by DHCP.

    Port 4 is connected to L2 Switch (Cisco) and then distributed to all the users.

    Port 3 is connected to L3 Switch (Cisco) and then connected to Server through Gigabit PoE Switch.

    We tried Using Fortinet firewall with the same setup and able to ping form Port 3 to Port 4 and vice versa

  • What do your tracerts show from the clients? And are there any static route entries? Is your L3 switch running any static routes as well? Perhaps one that was in use when you had a Fortinet in place.  I was trying to recreate this issue on an XG, XGS and Virtual Sophos Firewall, none of which display this symptom.  Would usually happen if there are incorrect routes, subnets or gateways involved on either a client, L3 switch route entry, or worst case scenario, try rebooting the XG firewall and see if it conitnues to do the same or ensure you are running the latest firmwares.

Reply
  • What do your tracerts show from the clients? And are there any static route entries? Is your L3 switch running any static routes as well? Perhaps one that was in use when you had a Fortinet in place.  I was trying to recreate this issue on an XG, XGS and Virtual Sophos Firewall, none of which display this symptom.  Would usually happen if there are incorrect routes, subnets or gateways involved on either a client, L3 switch route entry, or worst case scenario, try rebooting the XG firewall and see if it conitnues to do the same or ensure you are running the latest firmwares.

Children