Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Guest WiFi separate FW rules

I have an XG210 with 1 LAN and 1 WAN connection.  I created a VLAN 100 (interface 1.100) for guest wireless and it is working fine but I want to allow all traffic for the guest network.  I created a new FW rule but the traffic is restricted like the default LAN unless I change the rule to ANY > ANY > ANY.  If I choose the 1.100 interface it becomes restricted.  Any tips?  This is my first XG device but I've been banging my head trying to figure this out.



This thread was automatically locked due to age.
Parents
  • Brandon,

    welcome to Sophos Community. Take note that XG uses Zones, which can be thougth are virtual entities to group multiple network objects. So when you have created the VLAN, you also have assigned it to a zone (LAN).So, you can create an additional zone (Guest-Wifi) and then use the new zone inside firewall rules. For example, Guest-Wifi to WAN traffic is allowed for only those protocols: http,https).

    The other option you have is to keep the new VLAN to lan zone and use source network. Create a proper subnet, IP range that takes the entire VLAN 100 and then proceed with the Firewall rule.

    Do not use as source network: ports, vlan ports.

    Regards

Reply
  • Brandon,

    welcome to Sophos Community. Take note that XG uses Zones, which can be thougth are virtual entities to group multiple network objects. So when you have created the VLAN, you also have assigned it to a zone (LAN).So, you can create an additional zone (Guest-Wifi) and then use the new zone inside firewall rules. For example, Guest-Wifi to WAN traffic is allowed for only those protocols: http,https).

    The other option you have is to keep the new VLAN to lan zone and use source network. Create a proper subnet, IP range that takes the entire VLAN 100 and then proceed with the Firewall rule.

    Do not use as source network: ports, vlan ports.

    Regards

Children
No Data