Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trying to enable multiple port forwarding to DVR/webserver

OK, I'm trying to configure an XG135 to allow traffic from the public IP to a DVR/Webserver located on a separate VLAN on my internal network. The vendor indicates that I need multiple ports opened up (3 TCP ports, including 443 and 1 UDP port). I discovered that Sophos treats this as a webserver so I went ahead and purchased the Webserver protection license and added that to my firewall. Unfortunately I still can't get this to work. I've tried researching this on the forums and knowledge base, but haven't found a good answer. It looks like I should be using the DNAT/Full NAT/Load Balancing Business Application template in order to configure the port list, but when I do this those ports still aren't showing up as Open when I run an external port scan (and the DVR app doesn't connect). I also tried use the Web Server Protection (WAF) rules, but it looks like that's really only designed for use with port 80 or 443. I did try configuring multiple rules using the Web Server Protection template; 1 for each port, and that worked as far as showing the ports open, but I still couldn't get the DVR app to work. Does anyone have any ideas as to why when I use the DNAT template the ports don't show as open? I'm running SFOS 16.01.2. Thanks!



This thread was automatically locked due to age.
  • I have connected to Dan Environment and all the BAR were correclty configured. No mistakes. Dan did not try for a couple of days (it was not working 2 days ago) and magically the XG started to forwarded the traffic from WAN to DVR Device.

    It is strange. I remember another guy on the community having the same issue and only after a couple of day XG started to allow traffic from WAN.

    I told to Dan to turn the BAR off and on again and test if the traffic is allowed. The other advice was to open a ticket with Sophos Support.

  • Thanks again to Luk for taking a look. I don't know why, but now the DNAT is working as intended. Last time I tested was on Wednesday and it wasn't working so I reverted my DVR to the old network until I could get this resolved. Then today when Luk logged in I switched the DVR back to the new network and everything is working. Now I know how my users feel when I come to investigate an issue and the computer is no longer acting up! 

    I did try disabling and re-enabling the DNAT rules and no change; the firewall is still allowing the traffic. I can open a ticket, but I'm not sure what Sophos support could tell me at this point.