This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Running Sophos XG in OpenStack

Has anyone done that yet?

We are currently trying to setup a Sophos XG 19.0.1 kvm version in OpenStack. Installation runs seemlessly. But when trying to get network traffic from LAN to WAN nothing happens. It seems as if the traffic is not getting back from WAN to LAN. Our OpenStack provider is unable to help us. They don't know anything about Sophos firewalls.

The setup in OpenStack is as follows:

2 Core CPU
40GB disk
1x LAN Port with port security disabled
1x WAN Port with port security disabled
no security groups added

We can ping and do name lookup from the WAN port without any problem. Trying the same from the LAN port fails with "Host unreachable". We tried everything we can think of till now, but don't get the LAN to run. LAN to LAN connections work.

Can anyone help?



This thread was automatically locked due to age.

Top Replies

  • First, I got it to work now. Problem was the port security and the default security group on the virtual firewall instanz. I disabled the port security on both LAN/WAN and gave the firewall instanz no default security group.

    To answer your questions:
    Deploy of SFOS as ISO file. Installed onto disk.
    First only disabled Port Security on LAN, WAN was enabled. Traffic was not working. Now LAN/WAN are disabled and traffic is going through to the firewall and LAN. Also no Security Group was added to the firewall instance.

    Jump to answer
Parents Reply Children
  • Does the log show if the traffic is hitting a NAT rule. If the traffic is not being seen returning it more than likely means you have a routing issue on the WAN interface connection.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.