Jump to content

Recommended Posts

Posted

I'm trying to get my iPads working with Smoothwall filtering. They will be working unauthenticated. I have the following configured:

 

- /24 subnet specifically for iPads, mapped to SSID MOBILE on WLAN controller

- Location MOBILE-WIFI mapped to MOBILE subnet in Guardian > Policy Objects > Locations

- Non-transparent authentication policy identifying MOBILE-WIFI by Location port 3128 in Web Proxy > Manage Policies

- MOBILE-WIFI Location mapped to Pupil group in Web Proxy > Ident by Location to manage applied filters

- Proxy settings applied by iPad configuration policy to point to “proxy:3128, no authentication” matching configuration of Location configured in Smoothwall

 

I still am unable to get web access on the iPads. Any help appreciated!

Posted
Just add interface under Network / Interface - give it the Vlan Tag ID and put it in the same address range as your scope, I just use Smoothwalls internal DHCP
Posted
The VLAN tagging is handled by the WLAN controller, as is DHCP. It seems I must set a parent interface, but I can't choose the internal LAN port over which the traffic will connect (Only ports 3-6 re available, but port 1 is the internal port).
Posted
It's a bit funny the way you do interfaces on Smoothwall, You have your basic interface, then you add VLANS to it wether or not they are tagged - you will need to create an Interface with your wifi VLAN
Posted

I have a basic interface configured for my LAN with the internal IP set, which is Port 1. Port 2 is the external connection. When I try to add the VLAN interface, I can't choose Port 1 as the parent interface and cannot proceed without choosing a parent. Ports 3-6 aren't patched in to anything; All internal traffic goes over Port 1.

 

There are several VLANs on our network (including three different WLAN VLANs), yet no VLANs interfaces are configured in Smoothwall and filtering is working fine with those (Windows, authenticated) devices.

Posted

So the Smoothwall can't identify what VLAN the iPads are on as all traffic simply identifies as "From the core switch" by the time it gets to the Smoothwall, with the core doing all the tag handling?

 

Well that's irritating -_-

Posted
It does sound like you are running the smoothwall transparently but I could be wrong, in that case your "Non-transparent" authentication policy identifying MOBILE-WIFI by Location port 3128 in Web Proxy > Manage Policies should be transparent ?
Posted
I have a transparent policy for port 80 which just seems to block all access; No errors, nothing in the traffic log. I just tried it on our Captive Portal network and everything works as expected, including SSL MitM.
Posted

So I resolved the issue... I was configuring proxy settings in the iPad profile, but configuring a transparent proxy in Smoothwall. Transparent proxy doesn't need proxy settings :confused2:

 

Friday was a long day... :closed_2:

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...