Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can I add Vlans onto the current LAN interface along with the default 172.16.16.16/24 network?

Hello,

 

I have been a long time Astaro v7 to UTM ver 9 user. My Old computer running UTM 9 died 4 weeks ago and I decided to use the XG VM machine on my ESXi 5.5 server.

I have installed it with 4 interfaces. Basically it is most basic default install and one firewall rule. Currently just using the two default LAN and WAN interfaces fresh out of the box as set up by the default install / Wizard. The default LAN is on 172.16.16.16. I had Vlans with my UTM v9, and I am trying to add Vlans to the XG.

I have reviewed all the posts concerning Vlans, not exactly finding the right similar question and answer.

Question, can the LAN interface still use the 172.16.16.16 address and then also add additional Vlan interfaces to the same LAN Ethernet port? UTM v9, you had to change from Ethernet interface to Vlan interface. Xg looks like I can just add additional sub interfaces (Vlans) to the default LAN interface.  Am I correct? From what I read, it looks like that can be done. I assume the 172.16.16.16 is on the default network / vlan 1, and that 172.16.16.16/24 can stay in place and be used as well as adding additional Vlans to the same LAN interface of other I.P. subnets?

 

What would be the basic config, and rules needed to say add Vlan 10 on 192.168.2.0/24 (Vlan interface / gateway on 192.168.2.1) so that it can go to the WAN as well as all other local Vlan's subnets including the 172.16.16.16/24?

My first thought was to keep the default LAN as it is and then take my interface C to add Vlans on interface C, but if I can just add Additional Vlans to my current LAN interface, Interface A I think it is. (I think interface A is LAN and interface B is WAN, correct me if I am wrong)

 

Ideas and suggestions?

Sincerely,

Chad



This thread was automatically locked due to age.
Parents
  • Chad,

    XG uses zone concept. You can create additional vlan on physical interface and create LAN to wan firewall rule where source network object is the single/multiple vlan.

    You cannot change the default physical vlan Id (vlan 1).

    Adding vlan is simple as adding an additional interface.

    Regards

  • Thank you,

    That was what I was thinking, so my LAN / Interface A which is already set up and work on 192.168.2.1 ( is already vlan 1 or native vlan. So all I need to do for interface A, the LAN, is add additional vlan 10  or as many vlan interfaces as needed to interface A. And yes set up my LAN to WAN rules.

     

    Thank you,

    Chad

Reply
  • Thank you,

    That was what I was thinking, so my LAN / Interface A which is already set up and work on 192.168.2.1 ( is already vlan 1 or native vlan. So all I need to do for interface A, the LAN, is add additional vlan 10  or as many vlan interfaces as needed to interface A. And yes set up my LAN to WAN rules.

     

    Thank you,

    Chad

Children
No Data