I have a ticket open for this already, but the problem has not been resolved. I'm pretty frustrated overall by this whole experience, so wanted to try tap into a wider pool of knowledge to see if anyone else has a similar setup, and if they had any similar issues.
I have five public IPs from my provider. One for personal/Home use, the other four are for my home based business use. These are the four that I have on my Sophos.
I have a Sophos XGS 126 hardware device.
- Port 2 (WAN) is set with the static IP xx.xx.xx.155/29
---- Alias - xx.xx.xx.156/32
---- Alias - xx.xx.xx.157/32
---- Alias - xx.xx.xx.158/32
- Port 1(LAN) has a static IP on the Interface, but has no real connectivity to my "business" networks.
- I have multiple VLANS on Port 1, each with their own /24 subnet, and this is where all of my "business" networks are connected.
- WAN IP 155 has two DNAT forward to two different servers, both of which work 100% perfectly. There are no issues with either of these servers running on this WAN IP together.
- WAN IP 156 has a single DNAT rule setup to point to a single internal server.
- WAN IP 157 has a single DNAT rule setup to point to an Nginx Reverse Proxy, which then communicates internally to the servers that it's proxying.
- WAN IP 158 has a single DNAT rule setup to point to a single internal server.
WAN IPs 156 - 158 have intermittent connectivity outside my network. Internally I can access every server and every service on them without any issue. No lag in loading, no errors returned, everything works. From the Internet, it's always hit or miss whether any of these services work. I have made various slight changes on the firewall NAT rules and DNAT rules, which have sometimes temporarily resolved the issue, but eventually the intermittent connectivity issues came back.
Originally I had each of these public IPs connected to their own individual virtual Sophos XG, and everything worked fine. I finally invested in a physical hardware device, and that's where the problems started after consolidating everything into the one device.
If anyone has any suggestions or insight on this, I am all ears at this point and am willing to try just about anything (as long as it's legal and doesn't leave marks!)
This thread was automatically locked due to age.