This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

all but one system works on xg firewall

Hey, so I have setup my first XG and everything is working as it should with the exception, one system of 14 can not access or ping anything. It is set to DHCP like the rest, gets and IP, subnet mask, DNS1&2 and gateway IP. Checking logs I see it look for Microsoft but won't access anything. I have the firewall set to allow all outbound, no users required. Even setup a policy just for it. It is a Windows 7 based system. Any suggestions?



This thread was automatically locked due to age.
  • Hi Roxana,

    Can you ping the gateway (XG) from the endpoint?

    Could you run a packet capture from the XG (from WebAdmin: Diagnostics > Packet Capture) as you run a continuous ping to 8.8.8.8? Use 'host 8.8.8.8' as your BPF String and please post the output for review.

    Thanks,

    Karlos

    Karlos
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.
  • I'm not able to turn packet capture on. When I do, it turns right back off. without 8.8.8.8 in the BPF String it will turn on, but once I add it, it turns back off. I've re-flashed the firmware update and still no go. Reset all settings and no go. It so weird. Every single system works but this one. It worked with the old router. It is turned to DHCP although I have tried static settings and still no go. Putting it back on the old router and it works again. But we don't want the old router. The unit doesn't have a monitor. It's a headless system. Instead it has a control panel on the front where you change all the settings and do network test but it won't do continuous. it runs Windows 7.

    Oh, and due to the nature of the control panel on the front, I can't choose where it tries to ping. It just always says network test failed ping google.com (8.8.8.8)

  • Roxana,

    use tcpdump commands from console:

    tcpdump "icmp and host x.x.x.x"

    I suspect that your Windows PC still remembers the old router mac-address. From command line, on Windows, type arp -a to check the gateway mac-address and use arp -d to delete the arp cache.

    Regards

  • So the company that manufactures this headless system finally gave me the permission needed to attach a monitor with keyboard/mouse as well as the admin login details so I'm driving back to the site tomorrow to tackle this system. Will update this once I get it running.

  • So I got in to the system yesterday and turns out, Windows Firewall was the issue. I was waiting on user input to select network type... Gotta love that crap. Which in turn is the reason the support centre for the headless system they made couldn't get in and said it was our firewall. Nope! I did my job right. It was Windows. Seems pointless now to have opened this thread. Thank you both for the help.