Jump to content

Recommended Posts

Posted

I am at the point of scapping VLANs and keeping everything on a flat network including my wireless and letting users struggle with the wireless authentication breaking when they move across site due to meraki and smoothwall not playing nicely!!!

 

I appear to have some kind of routing issue but no idea what or where!

 

My core switch is a DLINK DXS-3600-32S

Wirless system is Meraki

Smoothwall - S8 Appliance

 

I have created VLANs for my wired desktop and they work fine!

 

Since roaming breaks authentication with Meraki/Smoothwall - the only way around this is to make the wireless clients use smoothwall for DHCP!

 

Meraki Wireless

===============

Meraki APs are on VLAN1 - the SSID is tagged for VLAN220 and all relevant network ports have beem tagged accordingly.

 

 

Smoothwall box

==============

Internal network is plugging into Port 3 on Smootwall - interface address 10.16.119.254/21

Created VLAN interfaces on Port 4 and assigned IP addresses accordingly - eg. VLAN220 Interface IP - 10.16.223.254/22

I have configured smoothwall DHCP for VLAN220 interface (10.16.220.0 - 10.16.223.254 - 255.255.252.0) and wireless clients pick up VLAN220 IP addresses - all good.

 

When wireless clients browse the internet, transparent proxy isnt working - so clients are unable to use the internet.

 

I have had smoothwall remote in and take a look and they confirm my smoothwall configuration is correct and there is nothing more they can do as smoothwall is configured correctly meaning I have a routing issue on my core switch.

 

Smoothwall have told me -

You should not see any traffic for the 10.16.220.0/22 network on ethC (port 3), you should only see it on ethD.220 (port 4)

If you are seeing it on ethC, you still have misconfigured vlans somewhere on the core switch.

 

 

DLink Switch

============

All ports are tagged correctly

VLANs work fine for Wired clients

 

When do I need to look at and what commands do I use?

 

Altertnatively - can anyone recommend any companies that do VLAN work at a reasonable cost who can remote in and sort this out for me! Only downside is can raise an offical order as no finance staff are in until Sept!!

 

Cheers

Posted (edited)
I am at the point of scapping VLANs and keeping everything on a flat network including my wireless and letting users struggle with the wireless authentication breaking when they move across site due to meraki and smoothwall not playing nicely!!!

 

I appear to have some kind of routing issue but no idea what or where!

 

My core switch is a DLINK DXS-3600-32S

Wirless system is Meraki

Smoothwall - S8 Appliance

 

I have created VLANs for my wired desktop and they work fine!

 

Since roaming breaks authentication with Meraki/Smoothwall - the only way around this is to make the wireless clients use smoothwall for DHCP!

 

Meraki Wireless

===============

Meraki APs are on VLAN1 - the SSID is tagged for VLAN220 and all relevant network ports have beem tagged accordingly.

 

 

Smoothwall box

==============

Internal network is plugging into Port 3 on Smootwall - interface address 10.16.119.254/21

Created VLAN interfaces on Port 4 and assigned IP addresses accordingly - eg. VLAN220 Interface IP - 10.16.223.254/22

I have configured smoothwall DHCP for VLAN220 interface (10.16.220.0 - 10.16.223.254 - 255.255.252.0) and wireless clients pick up VLAN220 IP addresses - all good.

 

When wireless clients browse the internet, transparent proxy isnt working - so clients are unable to use the internet.

 

I have had smoothwall remote in and take a look and they confirm my smoothwall configuration is correct and there is nothing more they can do as smoothwall is configured correctly meaning I have a routing issue on my core switch.

 

Smoothwall have told me -

 

 

 

DLink Switch

============

All ports are tagged correctly

VLANs work fine for Wired clients

 

When do I need to look at and what commands do I use?

 

Altertnatively - can anyone recommend any companies that do VLAN work at a reasonable cost who can remote in and sort this out for me! Only downside is can raise an offical order as no finance staff are in until Sept!!

 

Cheers

 

have you tried hardwiring a pc into the vlan 220 so you can do a bit of troubleshooting there? if you can ping the smoothwall interface it should be routing ok? and the smoothwall is not accepting connections for some reason?

 

if the clients are receiving ips from the smoothwall then surely routing isnt the problem?

 

did you create the transparent proxy for that network?

Edited by DGardiner
Posted

I have connected a laptop to a wired port on VLAN220 and it has picked up a correct ip (10.16.220.5/22) so DHCP on smoothwall is working correctly.

 

From the wired client I can ping VLAN220 gateway (10.16.223.254/22) so this would indicate that routing is working.

 

I can also ping the other devices on the network.

 

Smoothwall said the issue with the transparent proxy was because they see could traffic on ethC (port 3) instead of ethD.220 (port 4), this will stop the transparent proxy from working because its being seen on the wrong interface.

Once the traffic is forwarded to the Smoothwall on the 223.254 IP instead of the 119.254 IP, that should fix the transparent proxy for you.

 

Currently I am seeing traffic on port ports for 10.16.220.5/22 - Port 3 seems to be udp 137,138 traffic where as port 4 is seeing all kinds of traffic (presumable from the laptop trying to pull updates etc from the web)

 

Here are my Transparent Proxy

transproxy.png

 

 

Firewall rules.

firewallrules.png

Posted

Why is ethD plugged in?

 

It will act as the DG for Vlan220 which according to Smothwall is the cause of your issue.

 

Alternativly in the DHCP for the zone set the D-Link vlan 220 IP as the DG.

 

TT

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...