This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't access Synology server once Sophos XG Firewall is connected to Cisco switch

As I've worked through some (not all) setup issues, one that continues to stump me is the fact that when my NAS is connected to switch along with all other LAN devices and incoming internet from router, life is good. I can access my NAS no problem.

The minute I connect my router to Sophos XG V19 WAN (through bridge interface and one LAN port is connected to an open port on switch), I can connect to other LAN devices with exception being my NAS server. I can't ping the IP address either. Something is blocking access but I'm just not sure what it could be.

I also connected NAS directly to the Sophos XG device and that didn't make a difference. I've tried a couple of firewall rules and that didn't solve the issue. This same phenomenon happened on another firewall device with exception being I could connect NAS directly to the firewall device and access it but when I connected the NAS to my switch (my preferred connection method), I couldn't access or ping it.

So there has to be some setting within the NAS that is being blocked by XG that is unique from a PC, tablet or smart phone. I've scoured the internet and haven't found a solution.

ISP-->Router-->switch-->LAN devices (current state where NAS is accessible)

ISP-->Router-->Sophos XG-->switch-->LAN devices (future state where NAS is not accessible)

Also keep in mind, I'm learning as I go with Sophos XG so I may not completely understand suggested fixes so please bear with me.

Any help is definitely appreciated.



This thread was automatically locked due to age.
  • Hi Chevyavalanche  

    Please go to PROTECT-->Rules and Policies and add firewall rule as below : 

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Hey rfcat,

    The router is acting like a router as there is no bridge mode for the R8000. DHCP is handled by the R8000. I chose to bridge for 2 reasons:

    1. Wanted to keep current configs and static IPs as I have many.

    2. This same issue happened on before with another firewall unit so it would be easy to revert back to previous setup without XG firewall. I couldn't afford to shut my whole network down with XG acting as my router.

  • Yes, I had a rule like this a couple of days ago and it didn't fix my issue. It also caused my VPN router to lose connection (which is connected to a LAN port on XG).

  • Hi Chevyavalanche  

     Login to SSH with device console as per the link .

    Sophos XG and execute the below command and initiate ping from NAS 

    console>tcpdump 'host 172.16.0.3 and proto ICMP 

     console>dr 'host 172.16.0.3 and proto ICMP

    Also, check MONITOR & ANALYZE-->Diagnostics-->Packet Capture, click on Configure Enter BPF string host 172.16.0.3 and proto ICMP hit Save and turn on packet capture and share the status of packet flow
    Make sure to make a continuous ping to the destination IP 

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • I did the console>tcpdump 'host 172.16.0.3 and proto ICMP and the MONITOR & ANALYZE-->Diagnostics-->Packet Capture, click on Configure Enter BPF string host 172.16.0.3 and proto ICMP. The tcpdump continues to run. What or how do I provide you with info?

  • Hi Chevyavalanche  From GUI packet flow take snapshot and share use GreenShot or snipping tool and logs you got from putty select the logs and copy and paste it here

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Putty just gave me this error:

    I was doing the commands in the console from Sophos XG. 

    I don't do this kind of stuff everyday so you need to be very specific on how to do things. My setup before Sophos XG has been stable and running for years with little to no issues. I accessed everything easily. As soon as I add this firewall, all heck breaks loose. I am thankful you are taking the time to help a neophyte like me.

    The script from XG console is still running. do you want a snapshot of that? By the way, how do you stop it without quitting the console? I tried ESC key, CTRL-ESC?

    Here's a snippet from the XG console:

    172.16.1.24 is the NAS.

  • By the way, how do you stop it without quitting the console? I tried ESC key, CTRL-ESC?

    CTRL + c  and logs are not enough to investigate try again with SSH access 

    Please share the packet flow from GUI as well MONITOR & ANALYZE-->Diagnostics-->Packet Capture, click on Configure Enter BPF string host 172.16.0.3 and proto ICMP.  ?

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • I have over 200 pages and growing of this: MONITOR & ANALYZE-->Diagnostics-->Packet Capture, click on Configure Enter BPF string host 172.16.0.3 and proto ICMP. Keep going or stop and how do I share?

    Putty just gives me same error over and over again...but how do you enter this info?

    The 10.5.5.1 and Default RSA? I've tried to enter that info but can't seem to figure it out.

     

  • Keep going or stop and how do I share?

    install  snipping tool and share the snapshot for the packet flow you are able to see to stop the packet click on off 

    To get CLI access follow the below link you have to enter Sophos IP 

    https://support.sophos.com/support/s/article/KB-000038697?language=en_US 

    Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.