Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing traffic through wrong interface

Hi guys.

It is a bit complicated so I try to break down my problem as much as understandable.

I have a UTM SG310, running on current FW 9.604-2.

On this UTM, there are public IP adresses (/28), bound to eth1, connected to a corporate Internet-connection. On eth7, I have a dialup cable modem connection for my internal users accessing the web so that they don't use bandwidth on my corporate connection. So it looks like the following:

internal network -> UTM (eth1) -> public /28 network -> corporate Internet router from my ISP

internal network -> UTM (eth7) -> dialup modem (FritzBox)

Some weeks ago, I removed two of the IP (.10 and .14) that was bound to eth1 and put them on a different firewall, just for physical separation of DMZ and internal network. 

My problem is now, that accessing both IP (.10 and .14) gets handled different from my SG310:

1) accessing the .10 from my internal network gets routet as it should over eth7.

1.1) accessing the internet in general from my internal netweork gets routed as it should over eth7.

2) accessing the .14 from my internal network gets routed wrongly over eth1.

When attaching Wireshark between UTM's eth1 and my corporate Internet router, I see private IP adresses (I use for internal network) trying to access the internet.

I tried everything to get the traffic for .14 over eth7 but without success:

  • masquerading
  • nat rule
  • statical routing to the .14
  • multipath rule
  • rebooting the UTM 

All without access.

I am lost, does anybody have any idea or hint for me?

Best regards, Christian



This thread was automatically locked due to age.
Parents
  • Hi Christian,

    Is the .14 defined as a Host in the UTM? If so, my first idea would be to have a look at Definitions & Users, Network Definitions, and click the button labeled as "show where this object is in use". It might be a rule routing this Host thru ETH1 that you are not aware of. Or maybe the Host is member of a group that is treated somewhere.

    Basically there are two possibilities: The Host is routed according to your rules over ETH1, and you missed one of the rules. Or it is not covered by any rules and the general routing takes place over ETH1.

    If this doesn't work out, I hope someone else can help you further. It could be that there are some leftover rules which are not shown in the GUI. This could be fixed on command line. Or probably by deleting the host within the GUI and setting it up again.

    Good luck!

    Axel

  • This reply was deleted.
  • south side said:

    Don't use the wrong interface it will not be helpful in future to know about the interfaces

    What? Is this a Spambot?

Reply Children
No Data