We’ve had queries about allowing SOPHOS XG to pass VLAN traffic when in bridged mode.  By default the bridge mode option from the startup wizard needs some minor tweaking for it to pass all traffic as expected.  Based on firmware version SFOS 17.0.8 MR-8, this is the simple method to allow all VLAN traffic to pass through the bridge.

Set the XG into Bridge Mode during the setup wizard:

Disable routing on the bridge interface:


Create an ANY, ANY, ANY firewall rule with NAT disabled. This rule can later have filter policies added to it.