This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bridged mode vlan trunking between router and managed switch

I'm working on getting XG to pass tagged traffic through a bridged connection. Without the XG in place, the setup works, every host can access the internet and inter vlan routing is up.

The logs show no blocked or dropped traffic. When I take vlans out of the equation(config the router and switch for it) it all works as well.

     Here is a drawing of my set up.

I've referenced all the threads and KB I can and have not found a solution yet.

 

https://community.sophos.com/products/xg-firewall/f/network-and-routing/89867/sophos-xg-bridge-mode-in-multi-vlan-enviroment

https://community.sophos.com/products/xg-firewall/f/network-and-routing/73608/is-it-possible-to-configure-layer-2-sub-interfaces-in-bridge-mode

https://community.sophos.com/products/xg-firewall/f/sophos-xg-firewall-general-discussion/79646/how-to-setup-trunk-port-on-sophos-xg

https://community.sophos.com/products/xg-firewall/f/sophos-xg-firewall-general-discussion/75347/sophos-xg-between-two-trunk-ports

https://community.sophos.com/products/xg-firewall/f/cyberoam-to-xg-migration/76405/transparent-mode-between-trunk-links

https://community.sophos.com/kb/en-us/123508

 

I thought the last link was going to be the one, but after entering the commands, the only vlan to show up on the bridged interface was the last one I entered. I guess maybe this isn't possible or there is another way to add more than one vlan to an interface?



This thread was automatically locked due to age.
Parents
  • Eric,

    make sure you enabled "routing on the bridge" and a LAN to WAN, WAN to LAN rule exist.

    There are some limitation on bridging. There was even an AlanT thread and they will improve Bridge into next release....

  • I have a setup similar to Eric's, and I can't get this to work either. I did check that the "routing on bridge" was enabled.

    As of the static routes mentioned in one of the links, it makes little sense to me why they are needed. A bridge is a layer 2 device and should not have to know about routes, a layer 3 topic.

    About the WAN to LAN rule, what should it contain ?

    How does XG treat BPDUs ?

     

    Per AlanT, the bridging features will have to wait until v18.

Reply
  • I have a setup similar to Eric's, and I can't get this to work either. I did check that the "routing on bridge" was enabled.

    As of the static routes mentioned in one of the links, it makes little sense to me why they are needed. A bridge is a layer 2 device and should not have to know about routes, a layer 3 topic.

    About the WAN to LAN rule, what should it contain ?

    How does XG treat BPDUs ?

     

    Per AlanT, the bridging features will have to wait until v18.

Children
No Data