This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Uplinking 2 network switches on the same subnet to the XG

Does anyone know if it's possible to connect 2 switches to the XG firewall when both switches are on the same subnet. 1 switch contains servers and the other switch contains desktops, printers etc.

I would like to add both switches to the XG and have it route and check the traffic flowing between them, and route traffic to the web etc.

The reason for checking traffic from Lan to Lan is so that it could deny access to any desktop that has a 'Heartbeat' problem from accessing any of the servers on the other switch.

We tried it already with 2 ports on the XG set up in a bridge pair, but we suffered lots of connection issues between the desktops and servers and a lot of unhappy users when database applications failed, dns request failed etc etc. These failures happened even when our Lan to Lan policy had nothing turned on, not even the heartbeat detection. So I guess there was some kind of routing issue. So for now I've just linked the 2 switches directly together and then uplinked them to the XG for internet access, but without the protection of the servers from the desktops.

Should this be possible without completely re-configuring our existing network and putting the different switches into different IP ranges? 

(We have run tests on the network cards in the XG and everything passed so our problems weren't coming from faulty hardware, although I have noticed the fans spin up and down on a regular basis even though our average CPU usage is about 4% currently so I wouldn't have thought we're taxing the unit too much.)

Thanks.



This thread was automatically locked due to age.
  • I believe this is not possible for now as I haven't as yet managed to get it working in my environment. I had to use different subnets to uplink two switches which is not what I had wanted. I believe this is in feature request but when will it be implemented no ones knows as there are some other basic features like ssl vpn port which has yet not been implemented.
  • Hi waghelak,

    When you set up your subnets was it simply a matter of having to define the range/subnet on the different ports on the XG, or did you have to then reconfigure all your endpoints as well?

    I had heard that maybe subnets was the way to go and I've spent some time trying to unscramble our network switches to figure out the subnet splits, but I was hoping that any changes I made to the subnets would only need to be set on the XG.

    Is that what you had to do or did you also have to reconfigure every device attached to the switches for it to work?

  • Hi

    I didn't have to do any changes on end devices as I was using dhcp which sorted address side of things.  I had to re-IP few servers as I like it to be static.

    I have rules which now controls access over the two networks.

    Thanks