Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Noob needs help! - Migrating from pfSense to XG - No internet on LAN

First of all, thanks for the patience. I am a complete noob on XG, and I am trying to migrate from pfSense to Sophos XG, and I have read the other posts on the forum. As others have stated, I have internet within XG, and can ping google, and other web hostnames, however on LAN, I cannot ping anything on the web. I setup a rule to pass "any to any" and have also unchecked the "Match users" checkbox. This is the only thing I have done so far in the configuration. What am I doing missing or doing wrong? 

Thanks!



This thread was automatically locked due to age.
Parents
  • Please expand the rule so we can see what other features you have or have not enabled.

    Do have the NAT set in your rules?

  • Below are the details of the rule(s). I pretty much left everything at the default settings, until I understand what everything does:

  • Bryan,

    Traffic is not even hitting the firewall.

    Can you provide us more info about your configuration? Bridge, router mode? Are you computers using XG as default gateway (routing mide)?

    Thanks

  • My configuration (for testing) is as follows:

    WAN (Comcast modem) <--> Sophos XG Port 2 -- Sophos XG Machine -- Sophos XG Port 1 <--> 4 port unmanaged switch <--> Laptop

    I have Sophos set in gateway mode. Sophos receives DHCP address from WAN, laptop receives a DHCP address from Sophos, and can access GUI. I noticed that too, that there is no traffic shown in the firewall rule. I can ping websites, and also send test emails from the firewall, so the WAN is working, at least up to the firewall. I read some other posts that WAN/LAN routing has to be setup... is this something I need to do? Please let me know if you need any other information.

    Thanks!

  • In the firewall rule, I see "Primary Gateway = None" .  Select a gateway interface and see if that helps.

  • I set the primary gateway to Port 2- still no internet... BUT... it got me thinking. I set my laptop to a static IP, and have internet. I feel dumb for admitting this, but I looked in the firewall DHCP settings, and I didn't have a DHCP server setup. The reason behind this is a long story, but the moral of this story is: Don't try to configure a firewall while fighting a cold and in a NyQuil haze.

    Thanks to all for the help!

  • another random data point for anyone who lands here - on my pfsense box the LAN and WAN ports are the opposite way around from the default XG assumes.

    I.E WAN is port 1 and LAN is port 2 - i eventually worked out to swap my cables or swap the zones on the ports ;-0

Reply Children
No Data