I am pretty new to Sophos firewalls so this may seem a basic question. I want to set up an XG firewall at home with the possibility to remove it as simply as possible in case of issues. What I think will work is this:
WAN - VDSL to ISP
ISP Modem Router192.168.0.1 LAN address
192.168.0.1 LAN address static
|
WAN - Ethernet Port 2 - Bridge mode
Sophos XG, bridge mode on Lenovo PC, IP address for maintenance 192.168.0.2 static, no DHCP
LAN - Ethernet Port 1 - Bridge mode
|
WAN address - 192.168.0.3 static
ASUS DSL-AC52U Modem Router in Ethernet WAN mode (VDSL not used), used as DHCP server
Gateway address 192.168.0.1, DNS Server 192.168.0.1, 8.8.8.8, 8.8.8.4
LAN address - 192.168.1.1 static
| | \
24-port switch Main PC ASUS WiFi to other devices
|
Other network devices including other WiFi access points
So my questions:
- For the 192.168.0.x subnet, is the ISP modem at 192.168.0.1 the correct gateway and DNS? Does the SOPHOS XG look "transparent" in bridge mode if no firewall rules are set to block?
- If I simply set up the SOPHOS XG with a firewall rule to allow all traffic then will it pass all traffic without any users having to be identified? ie. Does it just allow unfiltered internet connections out of the box?
- Under this arrangement, should I be able to simply remove the SOPHOS XG by disconnecting it and plugging in a new cable straight from my ASUS WAN port to ISP modem LAN port? No further configuration changes required?
- For configuration and maintenance, can I access the SOPHOS XG from its WAN port if I unplug the LAN port and go straight from ASUS to ISP Modem/Router with another cable? This way I can fix stuff and play with settings while the Internet is working, then just plug the SOPHOS XG back in the line.
- I have a third network port on the SOPHOS XG. Can I configure this to a 192.168.1.x address and plug it into an ASUS LAN port to always have access to the SOPHOS XG for configuration?
- Can DHCP be retained in the ASUS router? If I do fixed IP allocation to certain MAC addresses in the ASUS router then will this allow me to do IP based rules in the SOPHOS XG?
- Once all setup, what is the simplest way to provide guest access to mobile phones (iPhone, Android mostly)? Most guests will be teenagers and I want to give them each maybe 2 hours of quota per day.
This thread was automatically locked due to age.