Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Replace Cisco 1921 With Sophos?

Not sure where this question would go other then Initial Setup.  It's more of a design question but its the closest group I could find.

 

Currently our main office has a Sophos XG310 and a Cisco 1921 used for a point to point connection with a branch office.  The point to point carries tagged info for three VLANs and has voice priority for DSCP EF (46) QoS and also for one of the three VLANs (kinda a backup in case the traffic wasn't tagged).  This works fine.  However we are adding another branch office and will have a Sophos XG125 in that office (for local internet).  Can the Sophos do the routing in place of a Cisco 1921 with the QoS?  In other words can I forward traffic from the main office (10.10.*) to the suboffice (10.20.*) with those three VLAN's and then give priority to the VLAN for voice traffic?  It would be nice to not have to have the Cisco boxes in addition to the Sophos at each location.

 

-Allan



This thread was automatically locked due to age.
Parents
  • Allan,

    if you have already an XG into place, you can have a look at the Policy Route options under Routing Menu. As you can see you can define routing source/destination, services and interface used and apply DSCP Marking.

    Please refer to XG Manual too:

    http://docs.sophos.com/nsg/sophos-firewall/v16050/Help/en-us/webhelp/onlinehelp/index.html#page/onlinehelp%2FPolicyRoutingEdit.html%23

    Regards

  • So looking at this I'm not sure if I understand correctly but I also don't think I gave enough information in the first post.

     

    Currently we have a setup like this with a point to point T1 line (1.5Mbps):

     

    The Cisco 1921s support VLAN encapsulation (http://www.cisco.com/web/techdoc/dc/reference/cli/nxos/commands/l2/encapsulation_dot1Q.html) so its internal ethernet has the three VLAN's on it.  It then sends this between the offices.  We then have QoS rules to guaranty bandwidth for both VLAN 20 and for DSCP 46.  However Ethernet Private Line just became available at both offices which is faster (10Mbps) and slightly cheaper then the T1 line.  The way they describe it was its a purely layer 2 pipe between the offices and I would handle all layer 3 routing. 

     

    Both Cisco 1921's have two Ethernet ports so I could pretty simply change the configs and use the secondary Ethernet ports for the point to point but now over the EPL instead of the T1 and not have to change any QoS or routing.  Or try to use the Sophos boxes at both ends and get rid of the Cisco boxes:

     

     

    So would that still fall under the policy route and also can I setup a interface wit the three VLANS, use the policy routing, and have it work exactly as it did with the Ciscos? 

     

    Also to add to this we are adding a third office soon so if I stick with the Cisco route I have to add two more.  If I can get away with the Sophos boxes I'd only add one of those to the new office because the XG310 at the "main" office has ports available.

     

    -Allan

  • Seems to me like this "magic" VLAN encapsulation just means the LAN port has tagged VLANs on it, those VLANs .
    Besides that, it's just routing, since VLANs on the left...have different IPs than VLANs on the right.

    Of course Sophos can do this routing.....but the QoS part....
    imho , XG ain't a star in the QoS department, it sums up all traffic to a single internal interface, where you can do limited QoS on.

Reply
  • Seems to me like this "magic" VLAN encapsulation just means the LAN port has tagged VLANs on it, those VLANs .
    Besides that, it's just routing, since VLANs on the left...have different IPs than VLANs on the right.

    Of course Sophos can do this routing.....but the QoS part....
    imho , XG ain't a star in the QoS department, it sums up all traffic to a single internal interface, where you can do limited QoS on.

Children
No Data