This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Does the Sophos XG lack PVID-assignment functionality !?

After having messed around with the webgui of Sophos XG (Home) on the HP T620 Plus & Intel I340-T4 NIC for a while, I have came to the conclusion that Sophos XG's VLAN feature set lacks the ability to assign PVID on the ports of the I340-T4. Having looked through some network maps of the troubleshooting posts here on the Sophos XG Forum, I found that most if not all of the working layouts consist of at least 1 802.1Q-compatible managed switch being connected to a VLAN interface of the XG via an RJ45 port. Only then that endpoint devices can be recognised and connected to the XG's network. Some example layouts can look like this :

Hence the conclusion. If this is true, then I believe that this is an Achilles Heel of the XG when compared to other router solutions, e.g. Ubiquiti's EdgeOS, which allows assigning PVID on every one of the router's LAN port:

I don't believe that adding the PVID functionality into the Sophos XG will cannibalise the sale of Sophos' managed switches, as Ubiquiti sell both their routers & managed switches very well.

Article on PVID: docs.oracle.com/.../index.html

Does Sophos plan to add this PVID functionality to its XG line of product later on or can I raise a feature request ?



This thread was automatically locked due to age.

Top Replies

  • Hi J

    I don't know if I completely understood your requirement, But I think this would be a workaround for your problem:

    - Create a bridge interface with that specific interface ( You will need to add another interface to bridge even if you don't need it. You should have spare interface )

    - Make sure "Enable routing on this bridge pair" is activated on bridge interface configuration so you could use bridge interface as routed interface.

    - On CLI, select 4.device console and use "system vlan-tag set interface" command to set a vlan tag for bridge interface.

    Jump to answer
Parents
  • Assigning a VLAN to a Port is likely a Switch Job. This would be likely interesting for smaller deployments, if they want to mix VLAN with LAN (bridging). But even smaller deployments which starts VLAN get a Switch in such terms. To do PVID on a firewall, this is actually something rarely requested. 

    __________________________________________________________________________________________________________________

  • In a homelab environment, not everyone can afford to buy a managed switch. Cheap stuff or knockoffs just do not meet expectation.


    It will be much appreciated if high-end switching capability can be added into Sophos XG. It will be almost perfect.

    The Ubiquiti EdgeRouter X SFP I am using has both routing, switching abilities as well as a basic firewall built in. I am considering moving to Sophos XG because of its hardened security features.

    It will be a steal for me if XG can have the PVID functionality added in later on with v19.5 for example. Much look forward to that. 

Reply
  • In a homelab environment, not everyone can afford to buy a managed switch. Cheap stuff or knockoffs just do not meet expectation.


    It will be much appreciated if high-end switching capability can be added into Sophos XG. It will be almost perfect.

    The Ubiquiti EdgeRouter X SFP I am using has both routing, switching abilities as well as a basic firewall built in. I am considering moving to Sophos XG because of its hardened security features.

    It will be a steal for me if XG can have the PVID functionality added in later on with v19.5 for example. Much look forward to that. 

Children
No Data