foofighterjim Posted October 1, 2021 Posted October 1, 2021 We upgraded from an older S8 appliance to a new S10 back in May, in my infinite wisdom I decided not to do a backup and restore but only copy the settings that were still relevant (we had a number of things setup that were not needed anymore). I have just discovered that our Smoothwall is not filtering in the manner I would expect, for instance; on our Domain DHCP location we use a non-transparent connection and this is working correctly, when removing the proxy settings however, the connection is completely unfiltered, previously the Smoothwall would have refused the request without the proxy information. I have also tried to configure our Guest SSID VLAN to take our standard staff level filtering but this too is bypassing the filtering altogether. I obviously have something fairly fundamental set incorrectly somewhere, I just don't know where. I have had a support call open for this for a few days but no sign of them investigating so far. I've even called and not been able to get through this morning, and I need to resolve the issue by this evening. If anyone has any ideas on things I could check it would be greatly appreciated.
MartinT Posted October 1, 2021 Posted October 1, 2021 Do you have a transparent proxy setup with no filtering policy? 1
ibpalle Posted October 1, 2021 Posted October 1, 2021 You should have a transparent proxy configured to filter devices that are not using proxy settings and if you have different interfaces for the LAN and WIFI a transparent proxy should be configured for both. One option when setting up the transparent proxy that can be easily overlooked, is the HTTPS option - that should be enabled otherwise HTTPS traffic wont be intercepted.
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 This is what we have for Transparent proxy: The BYOD setup is working fine, but the Guest VLAN is not being filtered despite directing to a group for no auth and then having a rule in guardian for that location and group.
ibpalle Posted October 1, 2021 Posted October 1, 2021 If you have changed the IP on the interface after you added the transparent proxy, edit and save the proxy policy again and restart the proxy service. When gateways/IPs are changed, sometime the transparent proxy has to be resaved and restarted as the Guardian conf rewrite isn't triggered by IP address changes. I am assuming the Smoothwall Guest Wifi IP address is the gateway for the clients?
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 If you have changed the IP on the interface after you added the transparent proxy, edit and save the proxy policy again and restart the proxy service. When gateways/IPs are changed, sometime the transparent proxy has to be resaved and restarted as the Guardian conf rewrite isn't triggered by IP address changes. I am assuming the Smoothwall Guest Wifi IP address is the gateway for the clients? An interesting thought, the main IP of the Smoothwall is the .49 address, this was originally different whilst I was running the old Smoothwall at the same time and copying settings. Unfortunately modifying the .49 policy, saving and restarting hasn't changed anything, I am still completely unfiltered without a proxy on any VLAN. Our core switch is the Gateway for the clients on the Guest SSID.
ibpalle Posted October 1, 2021 Posted October 1, 2021 And what is the gateway IP set in the routing table for the guest wifi? If the Smoothwall is directly on the Guest WIFI subnet, why not use the Smoothwall as the gateway?
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 And what is the gateway IP set in the routing table for the guest wifi? If the Smoothwall is directly on the Guest WIFI subnet, why not use the Smoothwall as the gateway? Gateway for the guest VLAN is 10.122.203.1 (the core switch), this is because we are not using the Smoothwall for DHCP of this VLAN. As mentioned, the unfiltered transparent issue is not isolated to this VLAN, it is happening on all VLANS with the exception of the BYOD.
ibpalle Posted October 1, 2021 Posted October 1, 2021 Gateway for the guest VLAN is 10.122.203.1 (the core switch), this is because we are not using the Smoothwall for DHCP of this VLAN. As mentioned, the unfiltered transparent issue is not isolated to this VLAN, it is happening on all VLANS with the exception of the BYOD. No need to use Smoothwall for DHCP in order to use Smoothwall as the gateway. What does a traceroute show going to 8.8.8.8 ?
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 No need to use Smoothwall for DHCP in order to use Smoothwall as the gateway. What does a traceroute show going to 8.8.8.8 ? Hop 1: Core switch Hop 2: Smoothwalls IP on that VLAN. Hop 3: Public IP Then eventually to Google.
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 Turns out that the Transparent connection policy on the .49 address needed to be enabled and HTTPS filtering needed to be on. This still doesn't drop the connection like the old appliance was but at least the content is filtered, it gives me something to work with at least.
ibpalle Posted October 1, 2021 Posted October 1, 2021 What do you mean 'drop the connection' ? And yes, the policy needs to be enabled and the option for HTTPS is sometimes overlooked.
foofighterjim Posted October 1, 2021 Author Posted October 1, 2021 What do you mean 'drop the connection' ? It used to actively drop the connection, it would not resolve anything without the correct proxy information.
ibpalle Posted October 11, 2021 Posted October 11, 2021 It used to actively drop the connection, it would not resolve anything without the correct proxy information. When you say the system won't resolve anything without proxy settings, then please check the DNS setup for the system. When a system is using proxy settings, the system sends all it's requests directly to the proxy. The proxy does the DNS lookup. When a system is behind a transparent proxy and is not using proxy settings, the system does it's own DNS lookups. If you have web access with proxy settings but are getting name resolution errors from your browser without proxy settings, DNS could be the culprit.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now