Jump to content

Recommended Posts

Posted

I'm not sure whether I've missed something along the way here but I'm about to add a BYOD WLAN to our wireless and point it to our smoothwall UTM. Currently our clients point to the smoothie as their proxy, which goes out through our firewall.

 

Now, before I even add the WLAN (which is where the authentication will be done, so the smoothwall side should be simple!) I've added DHCP to Port 5 on the smoothwall and given that an IP address. The DHCP server is set to give out addresses in that range and set the Port 5 address as the gateway, with 8.8.8.8 as the DNS server.

 

The interface Port 5 has its gateway set to our firewall (same as the Port 1 address used for 'normal' internal traffic) and has a transparent proxy set - so traffic on this port is given a default set of access rules (i.e 'Student')

 

To test this, I've plugged a laptop into Port 5 where it gets the correct IP and gateway, yet nothing works, DNS won't resolve and no traffic is allowed. The smoothie can ping the laptop and vice versa but I must have missed something at this stage. Once this works I will set up authentication via the wireless VLAN and we should be good to go!

 

Maybe I'm doing this an odd way, but as our smoothie is behind a firewall I want both normal and byod traffic to head out through the firewall, and the firewall allows all traffic outbound from our smoothie.

Posted

Two things which I did yesterday as I spent hours crying over it :p a) did you set a non-transparent proxy on it too? Without that mine wouldn't work at all even with a transparent enabled, b) did you set a pac file on said interface not just on the primary one? (Again mine didn't show as an option until I had a non-transparent enabled on it)

 

Steve

Posted

I've just got a transparent proxy on Port 5 - effectively I want the WLAN system to do most of the work and anything hitting this port goes out through the firewall with Student level filtering applied.

 

I did have a non transparent proxy initially, but it seemed to be an over complication?

Posted

Yep that's exactly what I tried yesterday and couldn't get to work. You can still use the transparent but I HAD to enable a non-transparent for things to start working.

 

No idea why, Tickets open with Smoothwall but not heard anything yet.

 

So I enabled a transparent and non-transparent on my port, Under WebProxy-Auto that port will then show up, and can be assigned a PAC file. (Wasn't showing until I enabled non-transparent). Then set a location so anything on that IP ranged auto gets set to Student/Guest etc

 

Steve

Posted
Hmm, I've got both trans/non trans at the moment and the auto config set on the Port 5 yet still get nothing. Might be time to restart the smoothie as well!
Posted

Do you have an upstream proxy enabled too like SWGFL etc? Only difference I can see you did is use google DNS while I used our upstreams, just wondering if there's no actual way for the client to work out what 8.8.8.8 is in your scenario

 

Also when you say you have the gateway set as your firewall does that mean it's not the smoothwall? Is there a route for this VLAN to get to the other firewall if that's the case?

 

Steve

Posted

I think this is where I'm going wrong. I have two basic interfaces configured (Port 1 for internal traffic and Port 5 for BYOD)

 

Both of these need to go out on a firewall which has an internal address (i.e on the same subnet as the Port 1) - which means I somehow have to route Port 5 to that, and that might not be possible and keeping seperation as well.

Posted

So as an example.

 

Firewall = 10.0.0.1

Smoothwall P1 = 10.0.0.2 and forwards to 10.0.0.1 (Gateway Address)

Smoothwall P5 = 192.0.0.1 and forwards to 10.0.0.1 (Gateway Address)

?

 

If that's the case there's no way for your P5 one to get to the firewall. We set the Smoothwall (P5 in your case) as the gateway for that VLAN. Then all the VLAN gets pointed to smoothwall who just pushes it external for internet.

 

Steve

  • Thanks 1
Posted (edited)
So as an example.

 

Firewall = 10.0.0.1

Smoothwall P1 = 10.0.0.2 and forwards to 10.0.0.1 (Gateway Address)

Smoothwall P5 = 192.0.0.1 and forwards to 10.0.0.1 (Gateway Address)

?

 

If that's the case there's no way for your P5 one to get to the firewall. We set the Smoothwall (P5 in your case) as the gateway for that VLAN. Then all the VLAN gets pointed to smoothwall who just pushes it external for internet.

 

Steve

 

That sums it up, so I either have to find a way to NAT Port 5 with Port 1 or remove the firewall from the equation somehow! The smoothwall can see the firewall, but only from Port 1 as the firewall has no address on the Port 5 range. Looks like a rethink for me.

Edited by Sheridan
Posted

Shouldn't need to do either. Unless I'm misunderstanding how you have it setup.

 

If Port 1 is internal traffic, and Port 5 is internal traffic. You should have another port that's directing the external traffic to your firewall right?

 

So as long as Smoothwall is the gateway it should push the traffic out over the External Port to your firewall.

 

Or did I misunderstand how your firewall comes into play?

 

Steve

Posted
Shouldn't need to do either. Unless I'm misunderstanding how you have it setup.

 

If Port 1 is internal traffic, and Port 5 is internal traffic. You should have another port that's directing the external traffic to your firewall right?

 

So as long as Smoothwall is the gateway it should push the traffic out over the External Port to your firewall.

 

Or did I misunderstand how your firewall comes into play?

 

Steve

 

Sort of, on Port 1 the gateway is the firewall, which has a port with an internal IP and a port with an external IP (attached to our ISP's router)

 

So Port 5 cannot see the firewall, and the firewall has no route to it - unless I NAT Port 5 through Port 1. Either that or redfine how the smoothwall routes through the firewall by maybe adding another port.

Posted

So are you going in and out on Port 1 after filtering? You're not going in on one port, and out on another?

 

Like Switch1->Smoothie->Switch1->Firewall->ISP?

 

If so not sure you would be able to segment it as all the traffic has to go back to the main network for any routing etc. Unless as you say you changed ports about :s Unless someone else has a magic idea

 

Steve

Posted
So are you going in and out on Port 1 after filtering? You're not going in on one port, and out on another?

 

Like Switch1->Smoothie->Switch1->Firewall->ISP?

 

If so not sure you would be able to segment it as all the traffic has to go back to the main network for any routing etc. Unless as you say you changed ports about :s Unless someone else has a magic idea

 

Steve

 

Yeah its not the ideal setup as the firewall was in place, and the smoothie added just for filtering internally. Now this has changed, I'll have to create a new way to link the smoothie to the firewall I guess.

 

Incidentally I did manage to use the SNAT policies to NAT traffic from Port 5 to Port 1 (not ideal but tests the theory) and the only thing that didn't work is the auto proxy config - set manually it worked ok though.

Posted

It might still work depending on your setup, as there shouldn't be anything to route it to your internal servers still, just means traffic would go on the same lan which isn't ideal etc.

 

But I mean like if they tried to for example access your internal VLE, it'd get pushed to the smoothwall (as in the gateway for that VLAN), and the DHCP/DNS server would push it off on the DNS up to Google which wouldn't be able to resolve it.

 

Steve

Posted
It might still work depending on your setup, as there shouldn't be anything to route it to your internal servers still, just means traffic would go on the same lan which isn't ideal etc.

 

But I mean like if they tried to for example access your internal VLE, it'd get pushed to the smoothwall (as in the gateway for that VLAN), and the DHCP/DNS server would push it off on the DNS up to Google which wouldn't be able to resolve it.

 

Steve

 

I think I might restructure this to be: local network > Smoothwall (as default gateway) > private address on smoothwall as external Port > private address on firewall > external address on firewall (ISP).

 

That way all traffic goes to the smoothwall as its the default gateway, and it then routes it through on private addresses to the firewall. That would mean nothing hits the firewall apart from the smoothwall. Assuming the smoothwall UTM is set to allow everything and not NAT the 'normal' traffic then the firewall rules would work as before.

 

I think that might work!

Posted

Cracked it, moved the smoothwall to use an external IP on the same range as the firewall, and with a bit of switch config they both go out independently. Means http/s traffic goes out via smoothwall, anything else is handled by the firewall. Drops the throughput on the firewall as well and now my byod port is working as expected.

 

Cheers for your comments and advice on this one, helped me sort out where I was going wrong!

Posted
This is good guide.

 

4 SSIDs 1 Secondary Academy ? BYOD WiFi Setup | my world of IT

 

 

Some of the config isnt needed e.g ip helpers on vlans with no ips. But it works and is nice and simple. Id look at gettting your firewall on an external interface of the smoothie though to simplify your setup.

 

Cheers I would be looking to simplify this in the future. The firewall is an old TMG which has been brilliant but in theory the Smoothie UTM could take over all of its duties.

Posted

I'm nearly there, set a new SSID on a new VLAN and set the tagging all the way back to the core switch. From the core switch a port connects directly to Port 5 on the smoothie which is running DHCP (and has the ip address)

 

I've got no routing enabled for this vlan, so in theory all devices should hit the smoothie for dhcp (which I know is working if I plug into port 5 directly) but nothing is getting an ip address

 

So basically I have: AP > vlan 80 > edge switch > vlan 80 > Core switch > directly to > smoothie (port 5)

 

Any ideas where I've gone wrong? I've got the tagging set the same as our current 'domain' ssid and thats working ok.

Posted

When you say "core directly to smoothie" what do you mean by directly? Is it still set at VLAN 80 on that connection? If not your path will be blocked at the core as it wouldn't know where it's going. (Unless you detagged it)

 

If you just plug a device straight into your core switch in a port that's set at 80 does it get anything? Ignoring all the wifi/edge parts.

 

We have all the edge parts as Tagged for the vlan, then the last one into smoothie Untagged at that vlan. (HP wise) Might be worth a try.

 

Steve

Posted (edited)
When you say "core directly to smoothie" what do you mean by directly? Is it still set at VLAN 80 on that connection? If not your path will be blocked at the core as it wouldn't know where it's going. (Unless you detagged it)

 

If you just plug a device straight into your core switch in a port that's set at 80 does it get anything? Ignoring all the wifi/edge parts.

 

We have all the edge parts as Tagged for the vlan, then the last one into smoothie Untagged at that vlan. (HP wise) Might be worth a try.

 

Steve

 

We have the AP ports taggeds, the edge switch uplink ports tagged and the core switch ports tagged (which is where are the edge switches meet, plus the port that connects directly to the smoothie). The port on the smoothie has the same vlan tagged and DHCP active on there.

 

The idea is this vlan is completely on the smoothie/wlan and doesn't route across our other subnets.

 

Edit: When I plug a device into another port (untagged on the same VLAN 80) I don't get any dhcp address, only if Iplug directly into the smoothie port. So it looks like my smoothie doesn't work with vlans or my switches

Edited by Sheridan
Posted
Are the packets leaving your core tagged or untagged?

 

You may need to add a vlan intergace to port 5 with port 80 tagged if they are leaving your core tagged

 

Thats whats I've got, an VLAN interface tagged 80 on Port 5. The core switch has 6 ports with incoming edge switches attached - these ports have all the VLANS tagged (i.e other wireless and VOIP) and the smoothwall is attached to another port also tagged but only with the 80. I've tried a mixture of tagging and untagging but my brain is fried and I think I've forgotten everything about vlans! :p

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...