Jump to content

Recommended Posts

Posted

We upgraded from an older S8 appliance to a new S10 back in May, in my infinite wisdom I decided not to do a backup and restore but only copy the settings that were still relevant (we had a number of things setup that were not needed anymore). I have just discovered that our Smoothwall is not filtering in the manner I would expect, for instance; on our Domain DHCP location we use a non-transparent connection and this is working correctly, when removing the proxy settings however, the connection is completely unfiltered, previously the Smoothwall would have refused the request without the proxy information. I have also tried to configure our Guest SSID VLAN to take our standard staff level filtering but this too is bypassing the filtering altogether.

 

I obviously have something fairly fundamental set incorrectly somewhere, I just don't know where. I have had a support call open for this for a few days but no sign of them investigating so far. I've even called and not been able to get through this morning, and I need to resolve the issue by this evening. If anyone has any ideas on things I could check it would be greatly appreciated.

Posted
You should have a transparent proxy configured to filter devices that are not using proxy settings and if you have different interfaces for the LAN and WIFI a transparent proxy should be configured for both. One option when setting up the transparent proxy that can be easily overlooked, is the HTTPS option - that should be enabled otherwise HTTPS traffic wont be intercepted.
Posted

This is what we have for Transparent proxy:

 

Transparent.jpg

 

The BYOD setup is working fine, but the Guest VLAN is not being filtered despite directing to a group for no auth and then having a rule in guardian for that location and group.

Posted

If you have changed the IP on the interface after you added the transparent proxy, edit and save the proxy policy again and restart the proxy service. When gateways/IPs are changed, sometime the transparent proxy has to be resaved and restarted as the Guardian conf rewrite isn't triggered by IP address changes.

 

I am assuming the Smoothwall Guest Wifi IP address is the gateway for the clients?

Posted
If you have changed the IP on the interface after you added the transparent proxy, edit and save the proxy policy again and restart the proxy service. When gateways/IPs are changed, sometime the transparent proxy has to be resaved and restarted as the Guardian conf rewrite isn't triggered by IP address changes.

 

I am assuming the Smoothwall Guest Wifi IP address is the gateway for the clients?

 

An interesting thought, the main IP of the Smoothwall is the .49 address, this was originally different whilst I was running the old Smoothwall at the same time and copying settings. Unfortunately modifying the .49 policy, saving and restarting hasn't changed anything, I am still completely unfiltered without a proxy on any VLAN.

 

Our core switch is the Gateway for the clients on the Guest SSID.

Posted
And what is the gateway IP set in the routing table for the guest wifi? If the Smoothwall is directly on the Guest WIFI subnet, why not use the Smoothwall as the gateway?
Posted
And what is the gateway IP set in the routing table for the guest wifi? If the Smoothwall is directly on the Guest WIFI subnet, why not use the Smoothwall as the gateway?

 

Gateway for the guest VLAN is 10.122.203.1 (the core switch), this is because we are not using the Smoothwall for DHCP of this VLAN.

 

As mentioned, the unfiltered transparent issue is not isolated to this VLAN, it is happening on all VLANS with the exception of the BYOD.

Posted
Gateway for the guest VLAN is 10.122.203.1 (the core switch), this is because we are not using the Smoothwall for DHCP of this VLAN.

 

As mentioned, the unfiltered transparent issue is not isolated to this VLAN, it is happening on all VLANS with the exception of the BYOD.

 

No need to use Smoothwall for DHCP in order to use Smoothwall as the gateway. What does a traceroute show going to 8.8.8.8 ?

Posted
No need to use Smoothwall for DHCP in order to use Smoothwall as the gateway. What does a traceroute show going to 8.8.8.8 ?

 

Hop 1: Core switch

Hop 2: Smoothwalls IP on that VLAN.

Hop 3: Public IP

 

Then eventually to Google.

Posted

Turns out that the Transparent connection policy on the .49 address needed to be enabled and HTTPS filtering needed to be on.

 

This still doesn't drop the connection like the old appliance was but at least the content is filtered, it gives me something to work with at least.

  • 2 weeks later...
Posted
It used to actively drop the connection, it would not resolve anything without the correct proxy information.

 

When you say the system won't resolve anything without proxy settings, then please check the DNS setup for the system. When a system is using proxy settings, the system sends all it's requests directly to the proxy. The proxy does the DNS lookup.

When a system is behind a transparent proxy and is not using proxy settings, the system does it's own DNS lookups.

 

If you have web access with proxy settings but are getting name resolution errors from your browser without proxy settings, DNS could be the culprit.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...