Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP issue with fixed IPs roaming from one to another interface

Hello, 

I have a Sophos Firewall XG330 (SFOS 19.0.0 GA-Build317), with many REDs distributed in different buildings. Each building has his own DHCP RED interface, but I've fixed some IPs. The problem is when someone with a static IP goes to another building (so a different LAN, but connected to the same UTM, when tunnel is up).
In this case, the user that has a static IP address on his phone or laptop, can't use the internet in the new DHCP RED interface, because his device keep the static IP of the previous LAN, where he's not anymore.

In the attached files, we have an example: some devices belong to a DHCP interface with LAN from 10.4.0.1 to 10.4.7.254. The IPs until 10.4.6.254 are reserved for the static IPs (image 1 and image 2) and the IP Range from 10.4.7.1 to 10.4.7.254 is destined for the dynamics IPs. Then, when a host of the first or second image (so one with a fixed IP between 10.4.0.1 and 10.4.6.254) has to go to another building (image 3), configured with another RED, and so another LAN (for example 192.168.84.101 - 192.168.84.200), he can't establish a connection, because his IP address remains 10.4.X.Y.

How can I resolve this?

Thanks for the help!

Image 1:

Image 2:



This thread was automatically locked due to age.
Parents
  • Check this: "Sophos Firewall: Devices not getting dynamic DHCP lease when a static MAC-IP reservation exists"

    https://support.sophos.com/support/s/article/KB-000036032?language=en_US


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  •  whether this works or not depends on how the devices are allowed to access the firewall. Organisations that have people moving between lans usually have the static address assigned to a dns entry or maybe a clientless entry, the XG dhcp server does not update any other tables. 
    ian

    the article would be excellent if it also included the ability to update dns and clientless tables.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  •  whether this works or not depends on how the devices are allowed to access the firewall. Organisations that have people moving between lans usually have the static address assigned to a dns entry or maybe a clientless entry, the XG dhcp server does not update any other tables. 
    ian

    the article would be excellent if it also included the ability to update dns and clientless tables.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data