Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bridge mode doubts NAT

Hello guys.

First of all I would like to thank you for taking the time to read my question.

I'm trying to understand the need for a NAT (MASQ) in bridge operating mode.

And one scenario, I have the need to leave Sophos Firewall (SF) in this mode and do only Web filtering.


So the environment is: ROUTER <-> SOPHOS <-> LAN

Sophos configured as bridge mode, with the routing flag unchecked.

Computers have internet access. When you enabled App control, everything works fine. When you enabled the web filter, some sites give conn_rst.

So I decided to create a nat rule, when creating the nat rule doing the translation of the source ip, the accesses work.

That way the router is only seeing a connection IP, but it wouldn't want to be like that.

Could someone tell me why the need for this MASQ and if there is a possibility to get around it?



This thread was automatically locked due to age.
Parents Reply
  • Hi Vivek Jagad.

    Routing is disabled on my bridge interface. This is the question of my doubt. I understand that I don't need to do the MASQ.

    Traffic is sent to the upstream device. We have internet. The problem is when I activate the Web Filter. I notice that I have a lot of dropped packages (Invalid Traffic) for the website. I can resolve this situation when I apply MASQ. My bridge interface continues with the routing option disabled:

    So I want to understand, why do I need MASQ to solve my problem when I'm using the web filter?

    This documentation:Bridge interfaces - Sophos Firewall

    Explain it: "Sophos Firewall drops traffic related to bridge interfaces without an IP address if the traffic matches a firewall rule with web proxy filtering or if it matches a NAT rule. These dropped packets aren't logged. To prevent packet drop because of NAT rules, you must specify the override source translation setting."

    I use an IP on the bridge interface:

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?