Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED 15 and Sophos XG configuration problem

Hello,

I'm experiencing problem with sophos red. 

We have this network scheme:

So i cant reach our network from PC connected directly to red device.

But I can ping from our network RED gateway, also from PC connected to red, i can ping to sophos XG gateway. Maybe you could help with this problem?

Also from our network i can reach red gateway. 

Red mode in standard unified. 



This thread was automatically locked due to age.
Parents
  • Hi,

    As I can see Cyberoam is intermediate firewall for LAN and XG hence, are you able to reach XG from the end points connected to RED. Next what rules and routes are defined in XG to forward the traffic from RED network towards Cyberoam?

    If the traffic is successfully passed through XG to Cyberoam then you need to contact Cyberoam support to verify the issue further.

    Thanks

  • Hi, 

    I'm able to reach XG from PC connected to RED. On XG where is only one static route, to route traffic from XG LAN To our network. No rules applied, because RED and LAN is on the same zone. The problem our XG gateway, because from XG console i can ping both sides. Our network and PC connected to red

  • Hi,

    Can you post a screenshot of the static route configurations ? 

    Take SSH to XG and go to Advance Shell.

    Execute tcpdump -nei any host x.x.x.x (endpoint of Red IP) ; start a ping and capture the logs. Post first 50 lines of the logs.

    Next, execute drppkt host x.x.x.x; monitor if any drop packets are captured here. 

    Thanks

Reply
  • Hi,

    Can you post a screenshot of the static route configurations ? 

    Take SSH to XG and go to Advance Shell.

    Execute tcpdump -nei any host x.x.x.x (endpoint of Red IP) ; start a ping and capture the logs. Post first 50 lines of the logs.

    Next, execute drppkt host x.x.x.x; monitor if any drop packets are captured here. 

    Thanks

Children
No Data