Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue between 2 SG210's when using 192.x public WAN addresses

We have several site's that we can't seem to get to talk to each other no matter what I've tried. I believe it's because our public IP's are all 192.17x.x.x and the UTM's are blocking the traffic. Our sites with older sonicwall's are not having this issue on the 192.x.x.x public space. I've tried to add rules to allow all traffic from the other specific 192 public IPs without luck. Is there a setting I'm missing?



This thread was automatically locked due to age.
  • sorry, don't understand ...

    Some questions:

    - users are able to access the internet from every site?

    - which IP addresses do you use within LAN

    - how should a site talk to the other? Do you build VPN?

    using 192.x.x.x as WAN is no problem.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Yes users can access the internet with no issues. The internal networks are all 10.x.x.x/24 with one 192.168.x.x/24 at each site for guest access. All guest access controls are done on the wireless controller to block their local access. We have some services at a few sites that need to be accessible from the outside which are working great except when you try to access them form another site with a UTM and the 192 wan address. Currently we route all these services through the mpls but I would like to set up failover VPNs in case the mpls fails. Even basic pings from one site to the other fail between devices that are both on this IP range.

  • Hi, Jim, and welcome to the UTM Community!

    Please give a specific example of something you want to work.  What IP connected to what IP.  If the MPLS goes down, what's the acceptable failover time to the VPN connection?  Do you have any reason to want to bridge an Ethernet segment in one location with one in the other location?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA