Nebula NCC blocked by firewall

2»

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,067  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @GiuseppeR ,

    When that DHCP Server Guard was enabled (green switch) it was impossible to get an IP from Sophos firewall.

    image.png

    From your description, we understand your sequence of events was as follows:

    1. The Switch connected to the Fritzbox router was able to get an IP address and connect to Nebula
    2. The DHCP Server Guard feature was enabled
    3. The Switch was unplugged from the Fritzbox router and connected to the Sophos firewall
    4. The Switch was unable to get an IP from the Sophos firewall
    5. The DHCP Server Guard feature was disabled
    6. The Switch was then able to get an IP from the Sophos firewall

    This behavior aligns with the DHCP Server Guard feature specification we mentioned earlier. In summary, the initial DHCP server (Fritzbox router) assigned an IP to your switch before it connected to the Sophos firewall, which prevented the switch from obtaining an IP from the Sophos firewall while DHCP Server Guard was enabled.

    Now the switch gets the IP in DHCP, but it has blocked ports:

    The Cloud Management screen indicates that TCP ports 4335 and 6667 are blocked.

    To verify this, connect your PC directly to the Sophos firewall and test connectivity to TCP ports 4335 and 6667. This will confirm whether these ports are blocked in your network.

  • GiuseppeR
    GiuseppeR Posts: 357  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector
    edited April 11

    Hello @Zyxel_Judy

    please let me me update the numbered list:

    1. The Switch connected to Zyxel lab inside my Company and it was able to get the IP with DHCP Guard active
    2. The Switch unplugged and connected to a mobile router 5G on the table of the client organization to check it before mounting inside the rack, anyway the switch was able to change its IP with DHCP Guard active
    3. The Switch was connected to Sophos with DHCP Guard active and it was unreachable, neither it had any IP (0.0.0.0 inside Sophos table)
    4. The Switch was working onsite as a switch (LAN, VLANs) but with zero Nebula/onpremise monitoring/management
    5. The Switch connected to the Fritzbox router was able to get an IP address and connect to Nebula with still having DHCP Guard active
    6. The DHCP Server Guard feature was disabled via Nebula because I wanted to test its compatibility with Sophos
    7. The Switch was unplugged from the Fritzbox router and connected to the Sophos firewall
    8. The Switch was able to get a dynamic IP from the Sophos firewall
    9. The Switch was then able to be managed onpremise and then unlocked right ports to link to Nebula

    Considering this behaviour I think that something is not compatible between DHCP Guard and Sophos

  • PeterUK
    PeterUK Posts: 3,727  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    With DHCP Guard you need to set a port where DHCP is Trusted

  • GiuseppeR
    GiuseppeR Posts: 357  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    Never used it:

    immagine.png

    Neither I see where to tell Nebula that DHCP is coming ONLY on port 20 out of 48 to be used for uplink and DHCP server

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,067  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @GiuseppeR ,

    Based on our lab testing, there are two ways to let your Fritzbox (or any routers) to obtain an IP address when the DHCP Server Guard feature is enabled on Nebula and it's not the first DHCP server connected to your switch:

    1. The DHCP server configuration of your Fritzbox router is identical to that of the mobile router. With the same subnet of two DHCP server, the switch can get the IP when connect to the second router.
    2. The network to be without any DHCP server for over 5 minutes. The DHCP Server Guard feature will time out after this period.

    We believe that if the Sophos DHCP server configuration matches the mobile router's configuration, or if you wait more than 5 minutes between disconnecting the switch from the initial router and connecting it to Sophos, the switch should successfully obtain an IP address even with DHCP Server Guard enabled.

  • GiuseppeR
    GiuseppeR Posts: 357  Master Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector
    edited April 15

    Hello @Zyxel_Judy

    I had not tried to use the same subnet on mobile router (the one put on the table of the client, before installing the switch inside rack) matching the one on the Sophos, so I don't know if that is working.

    Anyway active DHCP Guard had no problems going through my lab, the mobile router and the Fritzbox: all them had different subnets and the switch went on Nebula in short time.

    I think it's something related to Sophos config, but I have no password to check it.

    To give you more details as possible I can tell you that from the time when I switched off the switch to the end of its installation inside rack, including re-cabling the patch panel above it, I think that 30-40 minutes were gone.

    It could be useful to perform some tests inside client's network?

    I can plug in a PC to execute network tests if you need infos about Sophos config, I have free ports where to plug that PC:

    immagine.png

    As you can see something inside that Sophos config is disturbing smooth operations on that switch:

    immagine.png

    I'm at your disposal, best regards

Nebula Tips & Tricks