Jump to content

Recommended Posts

Posted

Afternoon Guys,

 

Someone explain this to me as I can't understand if I'm being dumb or I am understanding this correct and Smoothwall are just being annoying....

 

A client trying to access our own internal websites (Using Domain Name) via Smoothwall can't get to them as it's getting an access denied error.

 

On looking in logs it's being pushed externally and trying to come back in which is then getting blocked as a loop.

 

If I put on proxy bypass it works fine, just not while using their proxy.

 

Now internally on our DNS we have it setup to point that URL to our IP, so if you ping it it pings internally and works fine. But still going through Smoothwall it's being pushed external.

 

This never happened on our old firewall, and they want me to reconfigure our DNS to put in conditional fowarders to let Smoothwall route DNS etc, but from my point of view Smoothwall is setup wrong as if a client's asking for an internal IP server via URL (as pingable on that IP) it shouldn't be routed externally at all and whatever Smoothwall is doing it should just pass it internally without the need for it to be pushed outside?

 

Am I going mad or does that makes sense? :s

 

Steve

Posted
Are your using the Smoothwall internal DNS server ? If so I fixed this scenario at our site by adding the internal IP's of the servers to be addressed by URL to the Static DNS hosts list in Smoothwall. Works fine for us. We did it to allow people to access our webmail using the same url inside as they would outside.
Posted

It "should" be setup such that:

 

Clients asks for URL

Smoothwall checks DC1/2 for IP (External if not)

Routes clients

 

However it's still pushing the routing externally once it's got the IP from DC and looping so blocking itself, or it's looking directly outside and looping and blocking. Neither way seems to work from what they've been testing, thus the conversation on changing over all our DNS etc

 

The bit I don't get is why even once it's got the internal IP from our DC it's pushing it outside, and doing the same with Static DNS (not that I like that option as means putting 20~ subdomains in :p)

 

Steve

Posted

Is smoothwall connected to an upstream proxy? If so it will just proxy and pass all http/https tragic onto the upstream proxy regardless of the ip being a local address or not.

 

You can add a list of IP address to bypass the smoothwall proxy and go direct. I can't remember off the top of my head where it is in the menus. But adding the IPs to this list will do exactly what you are looking for. Give me a bell on the phone tomorrow and I'll point you where to set it up.

Posted
Is smoothwall connected to an upstream proxy? If so it will just proxy and pass all http/https tragic onto the upstream proxy regardless of the ip being a local address or not.

 

You can add a list of IP address to bypass the smoothwall proxy and go direct. I can't remember off the top of my head where it is in the menus. But adding the IPs to this list will do exactly what you are looking for. Give me a bell on the phone tomorrow and I'll point you where to set it up.

 

Aye it's upstreaming to the Grid.

 

There's the destination exceptions but apparently they only work on transparent proxies, and even those don't seem to work here. And there's the proxy filter which they already setup and both doing nothing as it's still pushing it outside once it gets the local IP :)

 

What have you got set up in Networking > Routing > Subnets? Do you have an entry for your internal network pointing to your core router?

 

Yep each VLAN has it's settings to the gateway.

 

 

 

See as an example even our SCCM server traffic for the agent authentication is getting hit, but Smoothwall itself agrees that it's resolving the IP:

 

10.XX.1.45 (MySCCM.xx.sch.uk)   


PING 10.XX.1.45 (10.XX.1.45) 56(84) bytes of data.
64 bytes from 10.XX.1.45: icmp_req=1 ttl=127 time=1.09 ms
64 bytes from 10.XX.1.45: icmp_req=2 ttl=127 time=0.958 ms
64 bytes from 10.XX.1.45: icmp_req=3 ttl=127 time=0.843 ms
64 bytes from 10.XX.1.45: icmp_req=4 ttl=127 time=0.632 ms
64 bytes from 10.XX.1.45: icmp_req=5 ttl=127 time=0.576 ms

--- 10.XX.1.45 ping statistics ---
5 packets transmitted, 5 received, 0% packet loss, time 4001ms
rtt min/avg/max/mdev = 0.576/0.821/1.096/0.195 ms

 

Yet still pushes it to the Grid:

 

The following error was encountered while trying to retrieve the URL: http://MySCCM.xx.sch.uk/

Unable to determine IP address from host name ‘MySCCM.xx.sch.uk’

The DNS server returned:
Name Error: The domain name does not exist.
This means that the cache was not able to resolve the hostname presented in the URL. Check if the address is correct.
Your cache administrator is [email protected].

Generated Thu, 17 Sep 2015 14:35:59 GMT by proxy04.th1.swgfl.ifl.net (squid)

 

 

Thanks,

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...