I recently switched from PFSENSE to Sophos XG and I am now running into some problems with Windows Server NLB.
I have a Windows Server cluster providing DNS and Web services. The cluster is configured to use Windows NLB in IGMP mode in order to increase availability and protect against outages.
Everything worked fine with pfsense (it was necessary to add a parameter: net.link.ether.inet.allow_multicast)
But now with Sophos XG I am no longer able to reach services configured on the NLB VIP.
Clients are able to ping the VIP, but any kind of service request (NSLOOKUP, DIG, HTTP, HTTPS) just times out. However, the XG firewall itself is able to communicate with the VIP successfully for both ping and services.
I added a static ARP entry for the VIP but this did not seem to make a difference.
I have searched all over but have not found any documentation regarding this problem.
I also checked the Sophos Firewall logs, but have not seen any indication as to what would cause the issue. In fact, i dont see any traffic trying to reach the Windows Server VIP.
I would greatly appreciate help and feedback in this matter.
This thread was automatically locked due to age.