<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network on Marko Apfel</title><link>http://blog.marko-apfel.de/topics/network/</link><description>Recent content in Network on Marko Apfel</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 22 Dec 2024 12:00:00 +0100</lastBuildDate><atom:link href="http://blog.marko-apfel.de/topics/network/index.xml" rel="self" type="application/rss+xml"/><item><title>Sophos XG Homelab: The Resulting Architecture and Lessons Learned</title><link>http://blog.marko-apfel.de/posts/resulting-architecture-and-lessons-learned/</link><pubDate>Sun, 22 Dec 2024 12:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/resulting-architecture-and-lessons-learned/</guid><description>Looking back at the finished segmented network: what worked, what caused confusion along the way, and the operational checklist that keeps it maintainable going forward.</description></item><item><title>Troubleshooting VLAN Connectivity with Sophos XG</title><link>http://blog.marko-apfel.de/posts/troubleshooting-vlan-connectivity/</link><pubDate>Tue, 10 Dec 2024 18:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/troubleshooting-vlan-connectivity/</guid><description>A layer-by-layer checklist for isolating VLAN connectivity failures — from cabling and tagging up through routing, firewall policy, and NAT — instead of guessing at fixes.</description></item><item><title>Using Dedicated Sophos XG Interfaces for Management and VLAN Traffic</title><link>http://blog.marko-apfel.de/posts/dedicated-interfaces-for-management-and-vlans/</link><pubDate>Tue, 10 Dec 2024 08:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/dedicated-interfaces-for-management-and-vlans/</guid><description>The single decision that paid off most in this project: keeping the WebAdmin path physically separate from the trunk being reconfigured, backed by a tested recovery procedure.</description></item><item><title>Separating IoT and Smart-Home Devices with Sophos XG</title><link>http://blog.marko-apfel.de/posts/separating-iot-and-smart-home-devices/</link><pubDate>Mon, 09 Dec 2024 12:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/separating-iot-and-smart-home-devices/</guid><description>Putting IoT devices in their own VLAN is only step one — this part works through placing MQTT and HomeMatic services deliberately, writing a flow matrix, and handling broken multicast discovery across VLAN boundaries.</description></item><item><title>Understanding Inter-VLAN Routing and Firewall Rules on Sophos XG</title><link>http://blog.marko-apfel.de/posts/inter-vlan-routing-and-firewall-rules/</link><pubDate>Sun, 08 Dec 2024 12:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/inter-vlan-routing-and-firewall-rules/</guid><description>Connected routes tell Sophos XG where a network is, not whether traffic may go there — a look at building specific, named, flow-based firewall rules instead of broad LAN-to-LAN allows.</description></item><item><title>Building a Dedicated Management Network with Sophos XG</title><link>http://blog.marko-apfel.de/posts/building-a-dedicated-management-network/</link><pubDate>Sun, 01 Dec 2024 12:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/building-a-dedicated-management-network/</guid><description>Why a management network should hold only management planes rather than every device that feels important, and how firewall rules and local service ACLs govern access to it differently.</description></item><item><title>Connecting Sophos XG to a Managed Switch with an 802.1Q Trunk</title><link>http://blog.marko-apfel.de/posts/connecting-a-managed-switch/</link><pubDate>Thu, 28 Nov 2024 12:00:00 +0100</pubDate><guid>http://blog.marko-apfel.de/posts/connecting-a-managed-switch/</guid><description>Getting the switch-to-firewall trunk right: access versus trunk ports, tagged versus native VLANs across Cisco and HP terminology, and a repeatable test procedure for adding each new VLAN safely.</description></item><item><title>Configuring VLAN Interfaces on Sophos XG</title><link>http://blog.marko-apfel.de/posts/configuring-vlan-interfaces/</link><pubDate>Sun, 13 Oct 2024 12:00:00 +0200</pubDate><guid>http://blog.marko-apfel.de/posts/configuring-vlan-interfaces/</guid><description>A walkthrough of creating VLAN interfaces, zones, and network objects on Sophos XG, plus a one-VLAN-at-a-time validation loop that keeps troubleshooting manageable.</description></item><item><title>Planning VLANs and IP Subnets for a Sophos XG Homelab</title><link>http://blog.marko-apfel.de/posts/planning-vlans-and-ip-subnets/</link><pubDate>Sun, 06 Oct 2024 12:00:00 +0200</pubDate><guid>http://blog.marko-apfel.de/posts/planning-vlans-and-ip-subnets/</guid><description>How to turn a trust-boundary model into disjoint VLAN IDs and subnets, avoid the overlapping-network trap, and keep DHCP, DNS, and migration steps documented as you go.</description></item><item><title>Designing a Segmented Home Network with Sophos XG</title><link>http://blog.marko-apfel.de/posts/designing-a-segmented-home-network/</link><pubDate>Sun, 29 Sep 2024 12:00:00 +0200</pubDate><guid>http://blog.marko-apfel.de/posts/designing-a-segmented-home-network/</guid><description>Why a flat home network breaks down once IoT, media, and management devices share one broadcast domain, and how trust boundaries — not VLAN numbers — should drive the design.</description></item></channel></rss>