Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SOPHOS XG Home Inter LAN Traffic

So, still in the middle of migrating from UTM9 to XG and experiencing growing pains.  Totally retooling my network and I am having trouble understanding a problem that I have run up against.  I have a managed switch that I have my wireless VLANs on (ports 1 and 2).  I also have an NVR connected to the same switch on port 3.  Ports 1-4,8 all have the PVID of 20.  On XG, I have assigned a static IP to the NVR and after rebooting, the NVR receives that IP address and it is properly assigned for the 20 VLAN, so I know that it is talking to the XG.  If I plug my laptop into port 4, I also get a proper IP address on the 20 VLAN, but I am not able to 'see' the NVR.  Ping returns 'host unreachable' or similar and all packets fail.

I guess my question is - does the traffic from my laptop go all the way back to the XG or does the switch send it straight to the NVR?  I am not a network pro or anything but as I understand it, the traffic should not go back to the XG.  Can someone educate me?  I have been wrestling with it for hours and I would appreciate it if someone could set me on the right path so that any more time that I spend is not wasted.  Also, I don't see any dropped traffic in the XG logs.

Here is my network map:

Thanks in advance for any assistance.



This thread was automatically locked due to age.
Parents
  • Ok, I figured it out.  I had a couple of things going on that I did not fully understand and accidentally fixing one led me to fixing the other.  Non-VLAN aware traffic that is going to traverse a VLAN has to travel over ports that are untagged.  I 'knew' that based on the research I had done regarding the switch and VLANs in general, but making changes to that setting did not make any difference, so I questioned its veracity.  

    The second part is that I had Client Isolation set up on the VLAN on the APs.  I misunderstood this feature to mean that the VLANs were separate from each other, but that is the nature of a VLAN in the first place.  Once I turned that off, the members of the same VLAN (both VLAN-aware and non VLAN-aware clients) were able to communicate.

    After fixing that, I went back to the VLAN settings on the switch and changed the incorrectly tagged ports to untagged and then everyone was happy.

    I am now seeing weird denied traffic in the logs and I have to start digging around in the rules and policies to figure that part out.

    Thanks to Prism and rfcat_vk for commenting.  You helped bump me in the right direction.

  • The denied traffic could be broadcasts or dead connections with the closing packets not being related to an active connection.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?