Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No WAN-Access from DMZ

Hi all,

for more than a week I'm trying to configure WAN-Access for a franking machine connected to the DMZ-Port and it's driving me nuts. The unit doesn't get access to the Internet and its franking service provider.

Here is the setup:

XG135, OS 18.5.2 MR2 Build 380 , Network Protection, Web Protection, static IP on WAN-Port (Sophos DSL-SFP modem)


DMZ on Port 3, DMZ-Network 192.168.8.x (/24), Port-IP 192.168.8.254, Zone DMZ
Zone DMZ: Member Port 3, Services DNS, SNMP
DHCP for DMZ on Port 3: Range from .11 to .20 (for service reasons only), Static IP set for the connected franking machine at 192.168.8.10; use interface IP as Gateway; DNS-Server uses devices DNS-Settings (internet provider DNS-Servers)

Firewall Rule (DMZ->WAN) allow/accept:
Source Zone DMZ, devices/networks any, all the time
Destination Zone WAN, Destination Networks any, Destination Services any
no filters or anything else
additional to that I also created a rule that is acting vice versa (allowing LAN traffic to the DMZ on Port 3 and Host franking machine)

Host and Services: Host (franking machine's name) + IP (192.168.8.10)

What else will I have to do to get the franking machine connected to the Internet so it can connect to it's service-servers (Pitney Bowes), retrieve service updates and charge it's credit for franking?
Actually I have no clue where I have to search for the issue...

Thanks in advance for any help!
Sebastian



This thread was automatically locked due to age.
Parents Reply Children
  • The issue appears to be the device does not have access to dns and hence it cannot make a connection.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hello again,
    I've reconfigured the franking machine again for using DHCP.
    The good thing is - it's able to find the providers DNS, the rule works.
    The bad thing - it tries to resolve the manufacturers server but - that's it. Nothing else happens.

    I've done a PCap - attached below. I Also checked if the manufacturers sever is alive and reachable - it is.

    Any suggestions?

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?