Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rules not working as expected

Hi,

I've rolled out many UTMs in the past and now starting to replace them with XGS, v19.

Pretty much makes sense but im puzzled by the firewall rules and how they are executed.

Here's one example that I dont get

I have simple LAN - 192.168.1.X that has Netgear wifi broadcasters attached to them.

I needed to create a guest network on those wifi broadcasters so created that with a VLAN, ID20, IP 192.168.100.x. Zone is LAN

Setup on the XGS the stuff required so Vlan interface, DHCP for vlan, etc etc.

The firewall rule is

All working fine, users are on guest, got internet, no problem. I can see clearly from the DHCP pool table that the guests are getting IP addresses for that Vlan segment.

However, as you see from the rule 0 B and 0 B for in and out.

I now wonder if the phones are just falling over to 4g because I look at the firewall logs and all I see is denies for anything from that network going out to the internet, not a single Allow.

Im really stumped because I dont know why its saying invalid packet or how to progress with this

Throwing a random idea but on UTM you had to create a masq rule for all networks needing the internet, I havent done that nor clicked on create NAT rule during the firewall rule setup. Should I have done or does the XGS handle that?

Many thanks in advance if you can help



Edited TAGs
[edited by: Erick Jan at 4:42 AM (GMT -8) on 15 Nov 2022]
Parents
  • You've set your Guest WiFi Network rule as #6. Are any of the five firewall rules above this also LAN-->WAN? Also your ___Guest_Wifi_Via___ is a host group covering the IP range 192.168.100.x? Is the DHCP specifying the gateway for that VLAN? If so, which port are you specifying on your firewall as the gateway for the VLAN?

  • Hi Wayne,

    There are no rules above Guest Wifi that is LAN to WAN

    The - ___Guest_Wifi_Vlan20 object is this

    IP version    IPv4
    Type    Network
    IP address  192.168.100.0
    Subnet /24 (255.255.255.0)
     

    The DHCP for this VLAN has "Use interface IP as gateway" ticked and auto fill with 192.168.100.1

    The last question, would you be kind enough to tell me where to check that?

Reply
  • Hi Wayne,

    There are no rules above Guest Wifi that is LAN to WAN

    The - ___Guest_Wifi_Vlan20 object is this

    IP version    IPv4
    Type    Network
    IP address  192.168.100.0
    Subnet /24 (255.255.255.0)
     

    The DHCP for this VLAN has "Use interface IP as gateway" ticked and auto fill with 192.168.100.1

    The last question, would you be kind enough to tell me where to check that?

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?