Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Please Helpme to configure the following scenario . We have 10 Sophos access points conected to sophosxg firewall and all these access points are connected to same dedicated switch .we need to create two ssid like guest and wlan and need to isolate guest

Please Help me to configure the following scenario  . We have 10 Sophos access points conected to sophosxg firewall and all these access points are connected to same dedicated switch  .we need to create two ssid like guest and wlan and need to isolate guest



This thread was automatically locked due to age.
  • From my perspective, it's not a goal of this community, to provide step-by-step solutions for people not having any expirience in XG Firewall. I'm sure, if you are starting to work some hours with XG Firewall, you can solve this situation by you self. As a Introduction, you'll find some further informations here https://community.sophos.com/kb/en-us/123219 

    If you have any further questions, because during your work, sophos XG is not behaving as it should, then feel free to contact the community again, it will be a pleasure to help you.

  • +1

     

    Also the isolation mode is the default one when you create a new wireless network, this means the OP didn't even tried to open the wireless section and click Add...

  • HI Pyarelal, 

    In your case if you need to connect multiple AP with a Common Switch and also want to create two SSID for each AP . Then you may need to consider VLAN in your network , You may create Multiple SSID and VLAN association for each to achieve isolation . 

    Requirements : You may configure  VLAN on XG interface and create a DHCP server accordingly .  Trunk connection is needed between XG --Switch--AP.  

    The Isolation is considered when two or more wireless clients are connected on the same AP .

  • The client isolation means that every device connected to the same SSID will not be able to reach each others.

    On the other hand I presumed the OP meant to isolate the traffic between the two SSID which can be achieved by selecting "Separate Zone" in the client traffic. This way you can even not configure any VLAN. The downside is that you can't have the same subnet in the SSID and on a wired interface