This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to setup DMZ on Sophos for my FiOs Router

Hi,
Looking for some help setting up a 3rd NIC on Sophos as a DMZ for my FiOs router to connect to. Lots of problems with FiOs TV service if there router is not first inline so I did have Sophos connected to FiOs router as DMZ and everything seemed to be working fine but I did not like the idea of having my wonderful Sophos double nat behind FiOS so now I would like to do the revers but I am having a bit of a problem. I followed this thread https://community.sophos.com/products/unified-threat-management/astaroorg/f/52/t/25961 and everything seems to be working except my remote DVR access so I am thinking that all inbound traffic from the WAN interface is not going to my DMZ interface, Am I correct?

Here is what I want to do, I want my DMZ interface to be wide open for both inbound and outbound but not allow the DMZ interface to access my LAN interface, Could someone please help me with how to set this up?

Sorry for the long post & thank you in advance..


This thread was automatically locked due to age.
Parents
  • I think you'll need the following DNAT rule (possibly as the last rule so you are still able to catch other traffic for other hosts inside your internal network.

    The destination should of course be your own FiOS router.....

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply
  • I think you'll need the following DNAT rule (possibly as the last rule so you are still able to catch other traffic for other hosts inside your internal network.

    The destination should of course be your own FiOS router.....

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Children
  • I think you'll need the following DNAT rule (possibly as the last rule so you are still able to catch other traffic for other hosts inside your internal network.

    The destination should of course be your own FiOS router.....


    Thank you for the extra tip. I am sorry to report that none of this seems to be working. I still cant get the remote DVR to work inless the main internet feed connects directly to the FiOs router WAN port. This is a real PITA[:(]