Jump to content

Recommended Posts

Posted

Currently our Smoothwall hostname is smoothwall.local I have been told by support that it needs to be a FQDN for WPA enterprise to do SSL interception.

 

How do I go about doing this? should I create a CNAME on the domain something like, smoothwall.domain.co.uk how do I point that to the LAN though? port forwarding? Like wise do I create a local DNS entry for smoothwall.domain.co.uk and point it to our webhost?

 

Do I need to change our whole local domain or can I just change the smoothwall domain address?

 

I'm a little lost as this isn't something I've done before. :(:confused:

Posted (edited)

You should be able to add another domain to your AD DNS servers. I've done it for our wifi controller. So wifi.school.co.uk points to 10.1.2.100 for example. I did it for the same reason - we wanted a real world certificate for our wifi authentication page.

 

The domain controller needs to be authoritive, but the domain doesn't need to be active directory integrated (I think from memory).

Edited by IrritableTech
Posted

I would alter the hostname of your Smoothwall box to smoothwall.domain.co.uk - just be aware if you've any certificates generated by/for Smoothwall you'll need to regenerate them.

 

You can alter the hostname in System -> Preferences -> Hostname

Posted
You should be able to add another domain to your AD DNS servers. I've done it for our wifi controller. So wifi.school.co.uk points to 10.1.2.100 for example. I did it for the same reason - we wanted a real world certificate for our wifi authentication page.

 

The domain controller needs to be authoritive, but the domain doesn't need to be active directory integrated (I think from memory).

 

How do I do that though? Do I need to create a new DNS Zone using the FQDN? The FQDN we have at the minute is just used for Google apps email. Have you created an A record on your server or webhost to point wifi.school.co.uk to 10.1.2.100?

Posted

Is it a primary or secondary zone I need to create? I would assume secondary as I already have a primary but looking at the add new zone wizard it appears it will let me create a new primary zone.

Sorry for the daft questions I've never really messed with DNS before and I don't want to break anything.

Posted

OK I think I've(you've :p) done it. I made a new primary zone and created the subdomain smooth.domain.co.uk and pointed it to the smoothwall IP 192.168.10.7 and I can ping it. Running nslookup on smooth.domain.co.uk brings back the correct IP.

 

Does that sound right?

 

So the next step is to make the CSR. I'll probably be back for more help on that. :p

Posted
I spoke to smoothwall support and he said that while, I can use the CA for the smoothwall interface it won't work for what I'm actually trying to achieve which conflicts with what support said yesterday.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...