Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connecting switch to XG Firewall

Hi,
we have CR50iNG Cyberoam which is upgraded to Sophos XG Firewall. We just wanted to connect additional HP procurve 5120 switch to network.
Sophos have allready connected two HP switches 2510 on port C and port D. Look at picture.


Someone who installed this network have created LAG interface of ports C and D. But switches are actually independent and not in cluster from their side.

It would be ideally to connect HP5120 using LAG with bundled 2G, but would also be ok if it just work on 1G.
Now configuration looks like this

I am not able to add vlan interfaces to this new LAG or even create new vlan interface (in system->hosts and services, type of system host). How is that?

Vlan section of network look like this

Working HP 2510 configuration:
ip default-gateway 10.10.19.254
vlan 1
   name "DEFAULT_VLAN"
   no ip address
   no untagged 1-24
exit
vlan 17
   name "VLAN17"
   tagged 23-24
   exit
vlan 18
name "VLAN18"
   untagged 19
   tagged 23-24
exit
vlan 19
   name "VLAN19"
   untagged 21-22
   ip address 10.10.19.253 255.255.255.0
tagged 23-24
exit


I tried many possible configuration but the only one who gets response in Sophos diagnostic (when pinging 5120 (ip 10.10.19.251) and selecting ping interface as new LAG interface) is this:

interface Vlan-interface1
   ip address 10.10.19.251 255.255.255.0

ip route-static 0.0.0.0 0.0.0.0 10.10.19.254

If I move this ip from Vlan-interface1 to Vlan-interface19 as in 2510 switches icmp requests times out from both sides.
Any ideas how to connect a switch to work?



This thread was automatically locked due to age.
  • Firmware SFOS 16.05.2 MR-2, but as I said it would be ok without LAG. How can I create separate VLAN interface? And with LAG configuration, should default gateway be LAN or LAG ip address?

  • How can I create new system host like LAN.21 for new VLAN interface? Because when i press Add in System -> Hosts and Sevices, there are no options for system host.

  • Ok it seems to hard questions from me. Then how to configure F port to connect pc with static IP so that it can reach internet?

  • Almis,

    configure an IP on the physical port, assign the port to a zone (you can use LAN or create a new one).

    Create proper firewall rule from (LAN or new created zone) to WAN.

    Those are the basics.

    Configure your pc to use the new physical port as default gateway.

    Regards

  • Ok,
    how to create system host type interface then?

  • HI ,

    In order to use LAG interface , you may need a switch which also have such capability and must not be connected to separate switches useless they are configured as Active-backup .  The VLAN is supported but the same is expected on the switch itself . Otherwise the function would not work .

  • But it is working solution which was implemented before me.
    So according to this solution two additional interfaces E and F were added to the same LAG interface:


    HP 5120 is not responding when connecting two ports 47-48(aggregated trunk), or only one port 46 (trunk) to firewall E,F and only E respectively. Still no luck. Any ideas?

  • Almis,

    can you share the HP Trunk and LACP configuration?

    Thanks

  • HP config

     

    <251>display current-configuration
    #
    version 5.20.99, Release 2221P20
    #
    sysname 251
    #
    clock timezone LT add 02:00:00
    clock summer-time LT repeating 03:00:00 2011 March last Sunday 04:00:00 2011 October last Sunday 01:00:00
    #
    irf mac-address persistent timer
    irf auto-update enable
    undo irf link-delay
    irf member 1 priority 31
    #
    domain default enable system
    #
    password-recovery enable
    #
    vlan 1
    #
    vlan 17 to 20
    #
    radius scheme system
    primary authentication 127.0.0.1 1645
    primary accounting 127.0.0.1 1646
    user-name-format without-domain
    #
    domain system
    access-limit disable
    state active
    idle-cut disable
    self-service-url disable
    #
    user-group system
    group-attribute allow-guest
    #
    local-user admin
    password cipher xx
    authorization-attribute work-directory flash:/
    authorization-attribute level 3
    service-type ssh terminal
    service-type web
    local-user backup
    password cipher xx
    authorization-attribute work-directory flash:/
    authorization-attribute level 2
    service-type ssh
    #
    stp mode rstp
    stp bpdu-protection
    stp enable
    #
    interface Bridge-Aggregation1
    port link-type trunk
    port trunk permit vlan 1 to 100
    link-aggregation mode dynamic
    dhcp-snooping trust
    #
    interface Bridge-Aggregation2
    #
    interface NULL0
    #
    interface Vlan-interface1
    ip address 10.10.19.251 255.255.255.0
    #
    interface Vlan-interface19
    #
    interface GigabitEthernet1/0/1
    port access vlan 20
    #
    interface GigabitEthernet1/0/2
    port access vlan 20
    #
    interface GigabitEthernet1/0/3
    port access vlan 20
    #
    interface GigabitEthernet1/0/4
    port access vlan 20
    #
    interface GigabitEthernet1/0/5
    port access vlan 20
    #
    interface GigabitEthernet1/0/6
    port access vlan 20
    #
    interface GigabitEthernet1/0/7
    port access vlan 20
    #
    interface GigabitEthernet1/0/8
    port access vlan 20
    #
    interface GigabitEthernet1/0/9
    port access vlan 20
    #
    interface GigabitEthernet1/0/10
    port access vlan 20
    #
    interface GigabitEthernet1/0/11
    port access vlan 20
    #
    interface GigabitEthernet1/0/12
    port access vlan 20
    #
    interface GigabitEthernet1/0/13
    port access vlan 20
    #
    interface GigabitEthernet1/0/14
    port access vlan 20
    #
    interface GigabitEthernet1/0/15
    port access vlan 20
    #
    interface GigabitEthernet1/0/16
    port access vlan 20
    #
    interface GigabitEthernet1/0/17
    port access vlan 20
    #
    interface GigabitEthernet1/0/18
    port access vlan 20
    #
    interface GigabitEthernet1/0/19
    port access vlan 20
    #
    interface GigabitEthernet1/0/20
    port access vlan 20
    #
    interface GigabitEthernet1/0/21
    port access vlan 20
    #
    interface GigabitEthernet1/0/22
    port access vlan 20
    #
    interface GigabitEthernet1/0/23
    port access vlan 20
    #
    interface GigabitEthernet1/0/24
    port access vlan 20
    #
    interface GigabitEthernet1/0/25
    port access vlan 20
    #
    interface GigabitEthernet1/0/26
    port access vlan 20
    #
    interface GigabitEthernet1/0/27
    port access vlan 20
    #
    interface GigabitEthernet1/0/28
    port access vlan 20
    #
    interface GigabitEthernet1/0/29
    port access vlan 20
    #
    interface GigabitEthernet1/0/30
    port access vlan 20
    #
    interface GigabitEthernet1/0/31
    port access vlan 20
    #
    interface GigabitEthernet1/0/32
    port access vlan 20
    #
    interface GigabitEthernet1/0/33
    #
    interface GigabitEthernet1/0/34
    #
    interface GigabitEthernet1/0/35
    #
    interface GigabitEthernet1/0/36
    #
    interface GigabitEthernet1/0/37
    #
    interface GigabitEthernet1/0/38
    #
    interface GigabitEthernet1/0/39
    #
    interface GigabitEthernet1/0/40
    #
    interface GigabitEthernet1/0/41
    #
    interface GigabitEthernet1/0/42
    #
    interface GigabitEthernet1/0/43
    #
    interface GigabitEthernet1/0/44
    #
    interface GigabitEthernet1/0/45
    port access vlan 19
    #
    interface GigabitEthernet1/0/46
    port link-type trunk
    port trunk permit vlan 1 to 100
    #
    interface GigabitEthernet1/0/47
    port link-type trunk
    port trunk permit vlan 1 to 100
    port link-aggregation group 1
    #
    interface GigabitEthernet1/0/48
    port link-type trunk
    port trunk permit vlan 1 to 100
    port link-aggregation group 1
    #
    interface GigabitEthernet1/0/49
    shutdown
    #
    interface GigabitEthernet1/0/50
    shutdown
    #
    interface GigabitEthernet1/0/51
    shutdown
    #
    interface GigabitEthernet1/0/52
    shutdown
    #
    interface Ten-GigabitEthernet1/1/1
    #
    interface Ten-GigabitEthernet1/1/2
    #
    interface Ten-GigabitEthernet1/2/1
    #
    interface Ten-GigabitEthernet1/2/2
    #
    dhcp-snooping
    #
    ip route-static 0.0.0.0 0.0.0.0 10.10.19.254
    #
    info-center loghost 10.10.70.14
    info-center loghost 10.10.84.111
    #
    snmp-agent
    snmp-agent local-engineid 800063A203D07E28BAAE7C
    snmp-agent community read netCOM2kro
    snmp-agent sys-info location x
    snmp-agent sys-info version v1 v2c
    #
    ntp-service unicast-server 10.10.70.4
    ntp-service unicast-server 10.10.70.5
    #
    ssh server enable
    sftp server enable
    ssh user test service-type scp authentication-type password
    ssh user admin service-type all authentication-type password
    ssh user backup service-type all authentication-type password
    #
    ftp server enable
    #
    load xml-configuration
    #
    user-interface aux 0
    user-interface vty 0 15
    authentication-mode scheme
    idle-timeout 45 0
    #
    return