Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Please help me troubleshoot my port forward rule

Hello everyone,

I am just an IT amateur first time trying out Sophos XG firewall v18. Here is my network map:

Where: VLAN 11 = Port 3.11; VLAN 1 = Port 4.1; VLAN 9 = Switch 0.9; VLAN 17 = Switch 0.17

Objective: I am trying to open the following ports on my 2 CCTV DVRs: 34xxx & 34yyy. Port 34xxx will be opened for both TCP & UDP traffics, while port 34yyy will be opened for TCP only.

Here are the screenshots of the firewall & NAT rules I have created. Prior to this, I had created an IP Host for the DVRs, assign them the IP addresses : 192.168.17.a & 192.168.17.b respectively.

Firewall Rule:

NAT Rule:

Within the protocol port selection, I chose like this:

Now that my policy test returned a failure.

I have been following this video clip on YouTube (Hindi language, Eng Sub available) to try port forwarding. The author of this video clip said that there is another method  beside this clip that can achieve the same result but I have not yet managed to find his tutorial on that method. Does anyone here in this forum know that '1st Method of Port Forwarding' ?

Please help me troubleshoot my rules. Thank you very much in advance.



This thread was automatically locked due to age.
  • Why are you trying to expose your security devices to the internet?

    most devices would connect to an external server which provides the secure connection. All initiated by the internal devices.

    the whole setup is way to complex, you do not have any VLANs in firewall rules. You do not appear to have assigned any ip networks to various VLANs.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Is the ip from your port1 the same ip as in the policy test or is it a public ip from your ISP?

    And as ian said - why are you trying to expose it to the internet? If you want to get access from the internet i would prefer a VPN connection.

    _______________________________________________________

    Sophos SG 210 with Sophos XG Home - 19.5 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for your reply. 8.8.8.8 is the public address of Google DNS.

    The port forwarding is necessary because the DVRs were not set up by me but by the technicians of the security firm. This system has been at my site for some long time ~ more than 10 years now. I need to port forward it so that I can view it remotely as well as via a smartphone app when I am away from site.

    Please help me with the port forwarding matter. Thank you very much buddy. 

  • I was asking which IP is bound to the port1 - your policy test can't work (if port1 is your wan/internet) as you tried, because you tried to reach the internal IP directly - you have to put your IP from port1 to your destination-field in the policy test.

    To be honest - if your firm did this you should consider to change the firm of security and IT-technical reasons. Just my opminion.

    _______________________________________________________

    Sophos SG 210 with Sophos XG Home - 19.5 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Do you mean I have to input my WAN IP in the Source IP field ?

    Are there any simpler ways to achieve port forwarding without having to set both the Firewall & NAT rules on Sophos XG v18 ?

    Well, actually, I am using this in a household environment. Yes, the computer is an ancient HP T620 Plus with a 128gb SSD and a 4-port Intel I340-T4 NIC equipped. I installed Sophos XG Home Edition v18 on this in order for it to replace my Ubiquiti EdgeRouter X SFP as the firewall router of my upcoming (dream) homelab setup.

    I am just an amateur and have no CCNA or any networking exprerience. Having successfully set up the EdgeRouter X SFP can be seen as quite an achievement for me in my opinion. I appreciate your patience and caring for my thread. Would you mind help me furthermore on this topic ?

    In the foreseeable future, I will be replacing these antique DVRs with the latest offerings from either Unifi Protect or any wireless CCTV systems. 

  • Hi,

    firstly, simplify your network by removing all your VLANs because they do not seem to serve any purpose, you have a VLAN on almost every port but no other network connection,'Next your Service definition is too broad needs to be something like 1:65536 to 34300:34500.

    As Wayne suggested setup your NVR as an endpoint for a VPN  that will improve your security and allow you access.

    When you replace the DVR it will more then likely connect to an external server to allow you to have remote acces without setting up any incoming firewall rules, further improving your network security.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hello   Forgive me for having forgotten to add the network layout map. I have now included it for you to have a better view on the layout of my Internet infrastructure and to answer why do I need several VLAN interfaces.

    As I will be implementing several UniFi APs to replace the current Linksys Velops at once for broadcasting several WiFi networks and using many IoT household appliances, VLANs become a necessity for security and maintenance. Thus, I had better create the VLAN interfaces as well as distinguish the Zones & IP Hosts.

    Pls take a look at it (again) at the top of my thread and kindly help me out on the troubleshooting. Thank you buddies very much.

  • Thank you  for the update.

    Some items for you to think about. You will need to terminate the VLANs on the XG, not the switch otherwise the XG firewall rules will not manage or log your traffic.

    The mesh wifi is just another LAN connection, so there is no need for a VLAN because you do not appear to have any other devices on that port.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for your advice.


    Firstly, I still don’t understand why do I have to remove the VLAN interfaces. Does it affect Internet connectivity and (or) firewall functionality of the Switch0 if there are VLAN interfaces bound to it ?

    Secondly, regarding the Hindi tutorial video with Eng Sub. The narrrator mentions that there is a method other than the one he and I are using to achieve port forwarding. Do you also know what is that method ? Does it work on Sophos XG v18 anymore ?

    Thanks again buddy. 

  • Hi,

    I am suggesting you remove the VLANs because they are not connected to the firewall, only the switch. If you want the VLANs, then you do not need a VLAN between the XG and the switch the VLANs should terminate on the XG if you want to pass traffic to them.

    Please post an expanded version of your network interface setup.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?