Jump to content

Recommended Posts

Posted

Hi all - I'm looking to set up another child node on a current Smoothwall setup of one existing parent and one child node.

 

Are there any walkthroughs for doing so?

 

...Is it horrendous work or simple enough?

 

Thanks all - bit nervy of it...

Posted

Its a simple process - the only pitfall is really just making sure the settings that are replicated are sound., Since you already have a working child I am assuming you are using an existing replication archive.

 

On the parent system, go to system - central management - settings and download the central management keyfile.

Again on the master, setup a profile for the child in the system - central management - child node settings. You should be able to just use the same settings you have for the existing child. Just replace IP/Hostname ofc.

Lastly on the child, go to system - central management - settings, select child node, upload the central management key.

The master needs to access the child on tcp port 222 (ssh admin port) so make sure that port has been opened in network - firewall - smoothwall access on the IP address/interface that the master is connecting to.

 

That should be it - go to the overview page on the master in central management and refresh the entry for the new child. You should start seeing information there.

  • Thanks 1
Posted

Gosh that was a quick reply! Thanks ibpalle!

 

Do you also have any dead simple installation/setup guides or is THIS ONE still current?

 

Thanks again!

Posted

Well it was as easy as that! Went through the install, ran the above... quick reboot and it's all there automatically; block lists, temp bans etc.

 

You're a gentleman ibpalle, thanks again.

 

Whilst I'm at it, are there any easy ways to bond the NICs in smoothwall?

 

Cheers enormously - that was painless. :)

Posted

Glad I could help.

 

Bonds are also simple, unless you are already using the interfaces you plan to put in the bond.

 

Simply go to networking - configuration - interfaces. Create a new interface using the button at the top right of the list. Select bond, name it and add the 2 interfaces you need to be part of the bond.

 

If you are already using one or both of the interfaces and they have an assigned IP, then those will need to be removed before the physical interface can be added to a bond, so you may need to go through some hoops to get that setup. Also, if you will be using this bond as a proxy interface and you are replicating proxy settings to the children, some additional care needs to be taken as the sequencing of the interfaces has to be the same on child and parent in order for the config to translate correctly.

 

If you are using the interfaces currently I would suggest contacting support to get assistance with this.

  • Thanks 1
Posted

Aight well I'll forget that part for now!

 

Also I spoke too soon, if I add this to the DNS round robin it asks users for authentication - any ideas where to look to sort that?

 

Thanks very much again, almost there.

Posted

Hi - set to Active Directory. This is Services > Authentication > Directories screen, right?

 

Status is a green tick and enabled, diagnostics running too but just seems to tick over - been running a few minutes.

Posted
I meant what auth method is the proxy set to use? We are using AD for verification of user credentials, but the proxy has to get those from somewhere so look at the web proxy - authentication - manage policies and tell me what auth method the proxy is set to use?
  • Thanks 1
Posted

Hi again - added it into the DNS RR just to try it and it is dropping everything it seems now, rather than asking for authorisation. Anything else I might do?

 

Thanks much btw.

Posted

I'd like to do a complete rework of that - for now try, from a normal client, to ping hostname(only) of Smoothwall - it should work and resolve to the correct IP.

 

If that works, change the auth method on the highlighted non-transparent proxy on port 3128 (I am assuming that's the one you mainly use) to be NTLM Identification (via redirect) and on the transparent proxy change the auth method to core authentication.

 

Save and restart the proxy service and test.

 

I would suggest you call support and go through a change process with them for this though - the change I proposed should be safe.

  • Thanks 1
Posted

Hi - thanks for that. Yes I did so, but as it's a child node the settings just change back when it's restarted.

 

I'll give support a ring.

 

Thanks again.

Posted
Just checking back in - all done! Robert got it sorted. NTLM seemed to work with both on Leeds 12.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...