Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Wireless Guest Network cannot access our public facing Web server

Hello all.  This is our basic setup:

 

Office A is on subnet 10.10.30.0/24

Web server (Hosted.com) is on subnet 10.10.200.0/24 AND 204.12.x.x/28 (the 204 network answers both internally and externally - configured this way by other IT staff due to needs of IIS/SQL applications)

Office A has both an "internal staff" wireless network (bridged), and a guest wireless network on a separate zone (172.16.30.0/24).

Wireless Guest Network does have access to UTM's DNS (which could be part of the issue)

UTM 9.412-2

 

 

 

Hosts on 10.10.30.0/24 can access Web server (both 10.10.200 or 204.12.x.x).  By design, wireless guests do not have access to LAN.  But there is now a need to have wireless guests have access to the Web server. 

 

From a wireless client:

I am unable to connect to any website on our Web server.

I cannot ping our Web server by name, internal IP, nor external IP.  I can ping other websites, such as yahoo.com.

I am not a firewall expert, so I am guessing here.  Since I cannot ping or access by IP, this is not a DNS issue (or at least not ONLY a DNS issue).

Guessed and tried some NAT, firewall, and policy routes, but either I am barking up the wrong tree, or not quite getting the correct settings.  And yes, I am somewhat clueless here.

 

Any help would be appreciated.



This thread was automatically locked due to age.
Parents
  • Does doing #1 in Rulz give you any clues?  If Web Filtering is active, do you have a Profile for the Guest Wireless network?  If not, you might find something interesting in Accessing Internal or DMZ Webserver from Internal Network.

    If you do have Web Filtering active, you might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address.  I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Does doing #1 in Rulz give you any clues?  If Web Filtering is active, do you have a Profile for the Guest Wireless network?  If not, you might find something interesting in Accessing Internal or DMZ Webserver from Internal Network.

    If you do have Web Filtering active, you might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address.  I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data