Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Using a bridge as a WAN interface?

We are setting up an HA pair of XGs, with redundant routers in front of the XGs. I'd like each XG to have a connection to each edge router (clustered). The easiest way to do this would be to configure the routers in failover mode, and use a bridge interface as the WAN on the XG, with one cable from each of the two ports in the XG bridge going to one of the two edge routers. It does not appear that the XG is capable of treating a bridge group as a WAN port. Is this the case?



This thread was automatically locked due to age.
Parents
  • For future reference, an XG will not let you configure a bridge group as a WAN port. Fortunately I have a pair of Mikrotik routers in front of the XGs, allowing for a great deal of flexibility. The Mikrotiks are running VRRP on the WAN side, and NATing the traffic from the XGs, so I can have one interface on each XG go to an interface on the router(s). This provides a fully meshed path from the edge to the network core.

Reply
  • For future reference, an XG will not let you configure a bridge group as a WAN port. Fortunately I have a pair of Mikrotik routers in front of the XGs, allowing for a great deal of flexibility. The Mikrotiks are running VRRP on the WAN side, and NATing the traffic from the XGs, so I can have one interface on each XG go to an interface on the router(s). This provides a fully meshed path from the edge to the network core.

Children
No Data