google.com<\/a>) and see if you get a response<\/p>","upvoteCount":0,"datePublished":"2023-05-02T14:59:09.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/2","author":{"@type":"Person","name":"jamespeterson5","url":"https://community.spiceworks.com/u/jamespeterson5"}},{"@type":"Answer","text":"Also I would check with support if you have it. In the past when I have had to make changes, their support had to go in and make changes via CLI.<\/p>","upvoteCount":0,"datePublished":"2023-05-02T15:27:15.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/3","author":{"@type":"Person","name":"taylorc","url":"https://community.spiceworks.com/u/taylorc"}},{"@type":"Answer","text":"
So have you created an interface on the router using the subnet 10.10.10.0/24 ? Do the PCs use this ip range (via dhcp etc) and have the router as their default gateway?
\nOn Sophos have you added the subnet 10.10.10.0 to the lan zone and made sure it is included in the allowed rules and the nat configuration?<\/p>\n
I would suspect the rules/na on the sophos as the issue. by default it will only be configured for the directly attached lan 10.10.20.0/24<\/p>\n
Further advice - change to a /30 mask on the sophos to Cisco as it is point to point so there only needs to be one ip at each end.
\nIs it actually a layer 3 switch not a router?<\/p>","upvoteCount":0,"datePublished":"2023-05-02T20:20:59.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/4","author":{"@type":"Person","name":"matt7863","url":"https://community.spiceworks.com/u/matt7863"}},{"@type":"Answer","text":"
hi thanks for reply,
\ni am able to get it work and ping 8888 without using LAG in sophos and Portchannel in cisco.
\nHowever when i switch to LAG and portchannel… i can only ping sophos.<\/p>\n
Does such rule in firewall exist for LAG and Portchannel? if so… how do i work around this<\/p>","upvoteCount":0,"datePublished":"2023-05-03T03:07:18.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/5","author":{"@type":"Person","name":"network-noob","url":"https://community.spiceworks.com/u/network-noob"}},{"@type":"Answer","text":"
Yes DHCP is created for 10.10.10.0/24 and PC gets the IP.
\nWhen im configuring without the LAG and Port channel interface i can get ping 8.8.8.8
\nIt’s only when i change the interface to LAG and Portchannel i can only ping up to sophos.<\/p>\n
And yes its a L3 switch as ive configured a point to point without LAG/Channelgroup and it works.<\/p>\n
The rules for Sophos is that LAG is on LAN ZONE.
\nSo there’s already a rule for LAN to WAN
\n“Source: LAN” → “Destination: WAN”<\/p>","upvoteCount":0,"datePublished":"2023-05-03T03:11:18.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/6","author":{"@type":"Person","name":"network-noob","url":"https://community.spiceworks.com/u/network-noob"}},{"@type":"Answer","text":"
so without the LAG, but still with a routed link it works, like this
\nsophos 10.10.20.1 - switch 10.10.20.2 and PCs 10.10.10.0/24 ?<\/p>\n
but add LAG and it fails?
\ndoes traceroute just timeout after sophos interface? what do the logs in sophos say happened to the packet? deny? or sent out wan?<\/p>\n
Double check that 10.10.10.0 is included in LAN zone of sophos.<\/p>","upvoteCount":0,"datePublished":"2023-05-03T06:52:46.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/7","author":{"@type":"Person","name":"matt7863","url":"https://community.spiceworks.com/u/matt7863"}},{"@type":"Answer","text":"
yes without LAG with routed link it<\/p>\n
sophos 10.10.20.1 - switch 10.10.20.2 and PCs 10.10.10.0/24
\njust as you have mentioned.<\/p>\n
traceroute ends at sophos IP<\/p>\n
10.10.10.0 is included in the LAN zone<\/p>","upvoteCount":0,"datePublished":"2023-05-05T14:01:20.000Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/8","author":{"@type":"Person","name":"network-noob","url":"https://community.spiceworks.com/u/network-noob"}},{"@type":"Answer","text":"
let me know if your issue is not resolved<\/p>","upvoteCount":0,"datePublished":"2024-10-20T09:30:15.832Z","url":"https://community.spiceworks.com/t/sophos-lag-to-cisco-issue/951146/9","author":{"@type":"Person","name":"spiceuser-9bjlx","url":"https://community.spiceworks.com/u/spiceuser-9bjlx"}}]}}