Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Rule Based on MAC address

Hi Sophos Community, Engineer and Architect

Good Day,

It seems that it is an easy Firewall rules based on MAC address.. but then something weird happened.

In our main office, I configured Firewall rules based on mac address and it 100% works- ----the blocking of specific websites etc.

BUT then in our branch office, I tried to configured firewall rule based on mac address and it does not work..

How come that this firewall rules does not work based on mac address???

It is XG 210 with firmware SFOS 16.05.2 MR 2

Thank you.



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Kunkka,

    Yes, that is how you configure a VLAN. You need to do that for each VLAN of your network and then, configure a trunk on your switch to send the tagged VLAN to the XG firewall.

    Your XG Firewall will be the default gateway of your PCs instead of the core switch.

    Best regards,

    Thibaut

  • Hi Sir ThibautVan der Kluft

    Good Day

    Thank you for your Professional response

    Can I configure multiple VLAN on ONE PORT?

    to MAXIMIZE PORT on FIREWALL.

    Here is the initial configuration of my network

    ON FWALL

    PORT 1 : 192.168.1.0/24 Network

    PORT 2 : 192.168.2.0/24 Network

    PORT 3 : 192.168.3.0/24 Network

    ON SWITCH:

    VLAN 1 = 192.168.1.0

    VLAN 2 = 192.168.2.0

    VLAN 3 = 192.168.3.0

     

    THEN,,,,,,

    I will Configure inter VLAN on my FWALL

    THIS will BE MY CONFIGURATION??

    VLAN on port 1

    with 3 Different Networks ....

    192.168.1.0

    192.168.2.0

    192.168.3.0

     

    TO maximize ports on my FWALL?
    It is possible sir?

    THANK YOU  

     

     

     

  • kunkka,

    of course you can. Add multiple VLAN on the same port and make sure that the switch port where the XG port is connected, transport all the VLAN you wish.

    Regards