Jump to content

HP / Smoothwall and VLANS - not happy!


Recommended Posts

Posted (edited)

I have recently taken over a network and Im struggling with what I envisaged to be a pretty simple task implementing Smoothwall having done it before.

 

Ill try and make it simple.

 

The network has various VLANS, I conntect my new smoothwall to the server vlan and give it an address.

I can talk to the box from other servers no problem.

 

I have a Staff vlan, I can rdp, ping talk etc to the servers from here.

I cannot talk at all to the smoothwall box.

 

Heres where it gets odd and I should probably have stopped because before this bit and left it at that!

I add a second interface on the smooth and bolt it onto my staff vlan, I enable external access to this port.

Fails.

 

From the Smoothwall I can ping servers and get a reply.

I cannot ping staff machines.

I regularly see Reverse Lookup failed at the top of the ping screen, a clue maybe!

 

#I have added the routes in Smoothwall for my staff vlan network, ive added in the server network to just for fun.

#I've enabled external access on these ports as well in smoothwall - but Id of thought Id of been able to ping them regardless?

 

Has anyone on any thoughts on why this issue maybe presenting itself?

 

Cheers.

 

Steve

Edited by steveJCUK
Posted
Don't have access to a Smoothwall these days (else I would send over some screenshots) but if I remember correctly it needs to have a route defined to get into your other networks.
Posted
Been a while, but I think you also need to add the vlan / network to :- System / Administration / External Access - caught me out a few times that one
Posted

what are your network ranges?

what are the DG's on each network?

what routes have you put in the Smoothwall?

do you have a central L3 switch for the vlans?

is the network to the smoothwall untagged on the server vlan?

 

TT

  • Thanks 1
  • 2 weeks later...
Posted (edited)

We have vlans for: Staff PCs, Student PCs, Printers, Phones, Servers, Management etc. pretty standard.

There is also a small scope in a VLAN for "Internet Out" so to speak. basically all this has in it is the firewall (172.26.233.219) - From here I can ping it from any machine, and I can ping any machine from the firewall. Good.

In the Core's config is IP-Route 0.0.0.0 0.0.0.0 172.26.233.219

What I really wanted to do was create a transparant bridge with the smoothwall. I gave this the IP address of 172.26.233.218 so it lived in the Internet VLAN 99.

The bridge gateway was 172.26.233.219. traffic did go up the bridge but to get back to its destination it would come back down the management side.

I should be able to just use the bridge with no management cable connected to port 1. As soon as port 1 was disconnected just leaving the bridge the internet would fail and I could no longer access smoothwall.

The servers connected to the core were all untagged. Smoothwall bridge was untagged in its Internet VLAN99.

Thoughts appreciated!!!!

Edited by steveJCUK
Posted

A running config output and bit of a simple description of your setup, removing any identifiable usernames, passwords or public IP's may be an idea.

 

i.e. From the looks of it I can see you have 2 8212 core switches and have setup VRRP to provide a common virtual gateway for vlans. What IP do your smoothwall routes point back to etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...