Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is there a way to reload the routing table without reloading the firewall?

Main firewall: XGS2100 at v.19.5
new Remote firewall: XG125w at v.19.5
old remote RED15

I am trying to migrate a remote site from RED15 to a site-site RED using a XG125w while keeping the remote LAN IP range intact.

I set up the new remote RED tunnel between the production main firewall and the new XG125w and made sure it's all working.

I then had someone at the remote site disconnected the RED15, disabled the RED interface/related DHCP on the main firewall, checked firewall rules, updated the static routes for the remote LAN (since it's now moved from the main firewall back to the new remote XG125), and updated the XG125 accordingly (LAN/bridge IP, DHCP, firewall rules etc.).

Now the new RED tunnel is up and running. But the remote LAN is not talking to the HQ. Packet capture on the HQ main firewall showed that return traffic for the remote LAN is still routed to the disabled REDS1 interface while the inbound traffic is received correctly on REDS2 via the new tunnel.

Is there a way to clear the routing table in GUI or CLI after the interface changes? I ran into a similar routing table issue on the same firewall in v.18. I ended up rebooting the firewall. But this is our main firewall handling 24x7 busineess communication. I would much prefer not having to schedule a downtime just for a test or reconfiguring a small site. 

And I hope I don't have to create a new LAN at the remote site because it will be a lot more work to migrate all the static devices to the new IP range without missing anything or breaking any service.

All input is appreciated!



This thread was automatically locked due to age.
Parents
  • Hello Daniel,

    Thank you for contacting the Sophos Community.

    Have you removed the RED15 interface in the Sophos Firewall or only disable it, if you have disable it, only try removing completely.

    Are you using Static Routes or SDWAN Routes? You could try switching and changing the route precedence from the backend to see if that works for you.

    Otherwise, I would ask internally about your question. 

    Regards


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Hi, Emmanuel.

    Sorry for the late reply. Sophos tech support shared a forum link with me. I was able to delete the static route tied to the disable REDS1 interface in Linux and make the testing of the new RED tunnel work. I've since gone on site with the new setup which required minimal configuration without having to reconfigure the remote IP subnet.

    Thanks very much for your help and that of the community!

    Daniel

Reply
  • Hi, Emmanuel.

    Sorry for the late reply. Sophos tech support shared a forum link with me. I was able to delete the static route tied to the disable REDS1 interface in Linux and make the testing of the new RED tunnel work. I've since gone on site with the new setup which required minimal configuration without having to reconfigure the remote IP subnet.

    Thanks very much for your help and that of the community!

    Daniel

Children