This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setting up Sophos UTM within ESXi6.5.0 2NIC's 2 VLAN's

Hi All,

I was running my Sophos UTM with the below config on a HP N54L with 2 NIC's quite well. I backed the UTM up and restored it onto my Dell T320 with 2NIC's but I am now having an issue with VLAN's which I am pretty sure has something to do with VMWare but thought I would ask here instead of the VMWare communities as it is more than likely now a config issue between the UTM and ESXi.

The UTM VM is as follows:

  • 2vCPU's
  • 4GB Ram
  • 100GB HDD
  • Network Adapter 1: VMNIC0 VM Network Physical Switch Port 0/9
  • Network Adapter 2: VMNIC1 NBN

Within the Networking section of VMWare I have:

  • VM Network With the UTM on ETH0 with VLAN ID 4095
  • NBN with the UTM on ETH1 with VLAN ID 0

 

I have 2 VLAN's setup on my Ubiquiti Edge Lite 24 Port Switch:

  • The ESX Host / VMNIC0 on Physical Switch Port 0/9 with VLAN ID 1 (Main allow all areas / adults access) and VLAN ID 50 (Kids extremely content filtered access)

 

Within the UTM --> Interfaces & Routing --> Interfaces I have:

  • Internal VMNic0 / ETH0 192.168.1.x/24
  • Kids VLAN VMNic0 / ETH0 192.168.44.x/24 VLAN TAG: 50
  • NBN / VNNic1 / ETH1 Public.ip.address/32 with a default gateway set to the public.default.gateway

 

Prior to the ESX host, if I jumped onto a tagged VLAN50 port I would get IP and be able to access the internet

Post ESX Host, If I jump onto a tagged VLAN50 port, I fail to get IP. If I statically assign an IP on the 192.168.44.x subnet I can't even ping the gateway (UTM)

It is not passing VLAN traffic or getting DHCP; Does anybody have any ideas since this was working when it was a physical UTM and not a VM.

 

P.S On a side note does anybody know what Guest OS I should be using? I read on Sophos that I need to be running SUSE Linux Enterprise 11 (64-Bit) But I am getting the following warning message within VMWare: The configured guest OS (SUSE Linux Enterprise 11 (64-bit) for this virtual machine does not match the guest that is currently running.

 

Thanks

 



This thread was automatically locked due to age.
Parents
  • I don't have too much experience with vmware, but it could be that VLAN 1 is the problem; you should not actively use VLAN 1 on a UTM since VLAN 1 is reserved for wireless.

    Try to change the VLAN ID for your Internal network and see if things get better.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply
  • I don't have too much experience with vmware, but it could be that VLAN 1 is the problem; you should not actively use VLAN 1 on a UTM since VLAN 1 is reserved for wireless.

    Try to change the VLAN ID for your Internal network and see if things get better.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Children
No Data