Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Rule Based on MAC address

Hi Sophos Community, Engineer and Architect

Good Day,

It seems that it is an easy Firewall rules based on MAC address.. but then something weird happened.

In our main office, I configured Firewall rules based on mac address and it 100% works- ----the blocking of specific websites etc.

BUT then in our branch office, I tried to configured firewall rule based on mac address and it does not work..

How come that this firewall rules does not work based on mac address???

It is XG 210 with firmware SFOS 16.05.2 MR 2

Thank you.



This thread was automatically locked due to age.
Parents
  • Hi Kunkka,

    Keep in mind that MAC addresses are used only on layer 2 communication and doesn't "survive" a router. On your branch office, is there any router between your LAN and your XG Firewall?

  • Hi Sir ThibautVan der Kluft,

    Good day

    IF ever there is a Core Switch between my LAN and a Firewall...

    what will be the effect of this?

    and what will be the solutions for this?

    Thank you

  • Hi Kunkka,

    A core switch which is doing inter-VLAN routing will prevent the XG firewall from getting the MAC addresses of the PCs.

    The only solution is to use the XG firewall to do the inter-VLAN routing. That means that you need to trunk all your VLANs to your XG Firewall and then configure each VLAN on it.

     

  • Hi Sir ThibautVan der Kluft,

    Thank you for your response.

    I attached screenshot on how to configure VLAN on SOPHOS XG?

    Can you verify if it's correct?

    Thank you very much ^^

  • Hi Kunkka,

    Yes, that is how you configure a VLAN. You need to do that for each VLAN of your network and then, configure a trunk on your switch to send the tagged VLAN to the XG firewall.

    Your XG Firewall will be the default gateway of your PCs instead of the core switch.

    Best regards,

    Thibaut

  • Hi Sir ThibautVan der Kluft

    Good Day

    Thank you for your Professional response

    Can I configure multiple VLAN on ONE PORT?

    to MAXIMIZE PORT on FIREWALL.

    Here is the initial configuration of my network

    ON FWALL

    PORT 1 : 192.168.1.0/24 Network

    PORT 2 : 192.168.2.0/24 Network

    PORT 3 : 192.168.3.0/24 Network

    ON SWITCH:

    VLAN 1 = 192.168.1.0

    VLAN 2 = 192.168.2.0

    VLAN 3 = 192.168.3.0

     

    THEN,,,,,,

    I will Configure inter VLAN on my FWALL

    THIS will BE MY CONFIGURATION??

    VLAN on port 1

    with 3 Different Networks ....

    192.168.1.0

    192.168.2.0

    192.168.3.0

     

    TO maximize ports on my FWALL?
    It is possible sir?

    THANK YOU  

     

     

     

Reply
  • Hi Sir ThibautVan der Kluft

    Good Day

    Thank you for your Professional response

    Can I configure multiple VLAN on ONE PORT?

    to MAXIMIZE PORT on FIREWALL.

    Here is the initial configuration of my network

    ON FWALL

    PORT 1 : 192.168.1.0/24 Network

    PORT 2 : 192.168.2.0/24 Network

    PORT 3 : 192.168.3.0/24 Network

    ON SWITCH:

    VLAN 1 = 192.168.1.0

    VLAN 2 = 192.168.2.0

    VLAN 3 = 192.168.3.0

     

    THEN,,,,,,

    I will Configure inter VLAN on my FWALL

    THIS will BE MY CONFIGURATION??

    VLAN on port 1

    with 3 Different Networks ....

    192.168.1.0

    192.168.2.0

    192.168.3.0

     

    TO maximize ports on my FWALL?
    It is possible sir?

    THANK YOU  

     

     

     

Children