Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG and a RED 60 Transparent/Split Mode configuration

Has anyone done one of these before successfully? I've had no problem with any of the Standard mode configurations, however this Transparent/Split one has given me a headache. I've even got a call open with Sophos and have had a lengthy call today were I was told the configuration was fine and it's a route missing from the remote site gateway. I did point out this doesn't seem to be documented anywhere, but apparently it is really,really the case. It didn't sound right and when I tried it there was no difference. It would also disagree with the description of how this works : 

"it is in-line with the gateway and can transparently redirect packets down the tunnel"

But the Sophos bod wouldn't have it.

The RED comes up, a laptop connected on the LAN side of the RED can still access the network at that end of things fine.

I've gotten a rule in to allow LAN < > RED traffic on the XG. All good so far.

I ping something on the XG side of things and nothing. If I run a TCPDUMP on the XG for traffic on the reds1 interface I can see the ICMP packets arrive, but not leave on any other interface. Nothing in CONNTRACK or DRPPKT. Oddly the firewall rule shows some traffic out on the RED firewall rule, namely a trickle DNS going from the core out to the remote network.

There seems to be a disconnect between the red network and the XG somewhere, it feels like I'm missing a step, but not what step is.

Please help shine a light onto this Dark World before I'm forced to burn this RED at the stake...

Regards



This thread was automatically locked due to age.
  • Do you have a route on the firewall as well? Basically RED Transparent / Split is a rare configuration. See: https://support.sophos.com/support/s/article/KB-000036699?language=en_US

    __________________________________________________________________________________________________________________

  • Thanks for answering, it is rare, but I'm guessing someone has it running somewhere successfully and it is sold as a working solution (if it works it's actually a good one for certain circumstances). The route on the XG is an interesting point, I can't see that shown step in the link that was posted, the XG log shows traffic destined for the remote LAN actually going down reds1 without a route anyway, and finally I tried a static route pointing at the reds1 interface (with no next hop) and it made no difference. This isn't the funky manual/split setup, just the standard Transparent/Split.

    I think the only person that can really any this one is someone that's got it working ok I think.

    Regards

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?