Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Any tips

After 4 months of frustration with the XG, I got the UTM installed on the XG 310 box.  Just thought I would throw that out here and ask if there are any bugs or tricks I need to be aware of.

Things I will need to do

1.  assigning external ip aliases to wan interface

2.  multiple NAT rules for on-the-premises servers

3.  do layer 3 routing using a router as the gateway to a datacenter

4.  for bypass asymmetric routing between the datacenter and my lan will need to bypass entire network/subnets on lan/wlan/vpn

5.  email mta protection for on-the-premises email server

6.  multiple ipsec-vpn policies

7.  SSL vpn user access

 



This thread was automatically locked due to age.
  • I have a router behind the firewall with a External and Internal IP.  The External IP of the router needs to be able to reach the gateway and the gateway needs to be connected to the internet.

    Can I just create new interface with the External IP of this router,check the box Proxy ARP and make a firewall rule to allow full ip between this router and a group of routers in another datacenter?

    Or should I create a DMZ and change the External IP of the Router to it to avoid complicating the routing table?

     

  • In general, our rule here is 'one topic per thread' so that specific questions can be answered by searching existing posts.  The UTM Community is also not a place to ask for a how-to, rather a place where one asks for help on specific issues.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob,  I just downloaded the UTM firmware to the XG 310 and trying to aggressively get it configured to make sure it will work.  After 4 months of trying to make the XG 310 work, the XG isn't ready for me.