Jump to content

Recommended Posts

Posted

I can't seem to find the documentation about how the smoothwall was originally set up, but I have only one internal interface / port set up on smoothwall and I would like to make some changes to it. In order to make the changes I want, I have to delete the IP address attached to the port. I am pretty sure I can't do all that from the one internal interface since deleting the IP would mean I'm no longer able to connect to that IP.How can I set up a second port on the smoothwall with a secondary IP that I can connect to so I can delete the original interface's stuff and rebuild?

 

So like smoothwall internal right now would be 192.168.1.1/24.

 

I want to be able to delete 192.168.1.1/24 and recreate it as an untagged vlan 192.168.1.1/24.

Posted

Setup a 2nd interface with a temporary IP and make sure that access to the admin UI is allowed on that interface in network - firewall - smoothwall access. Connect directly to that interface if you can using a laptop with ethernet and a static IP on the same subnet.

 

Once there, go through the config and go through the config in network - config and set any policy that relies on the 192.168.1.1 address to be a generic rule and not list that interface directly. Once done, you can delete the IP, then add a VLAN with the physical interface as the carrier.

Posted

I tried doing this and I must have missed a section. Does this also apply to the Web Proxy > Manage Policies page that has policies for transparent/non-transparent.

 

I did your steps and when I tried to add the VLAN interface I got the error shown in the attached photo. I thought I got everything but when I looked in the web proxy authentication manage policies I saw a bunch of "DELETED" lines. Think this is the cause or would I have missed something else?

 

Screen Shot 2021-10-17 at 6.57.08 PM.png

Posted (edited)

There is something else missing - the proxies wont prevent you from removing the IP.

 

Check port forwards, firewall policies, smoothwall access policies and any LLB pools that may have been defined and make sure the IP you are removing is not specifically listed in any of them. Any policy in the networking area that specifically lists the IP that is to be removed, will cause these types of error messages.

Edited by ibpalle
Posted
There is something else missing - the proxies wont prevent you from removing the IP.

 

Check port forwards, firewall policies, smoothwall access policies and any LLB pools that may have been defined and make sure the IP you are removing is not specifically listed in any of them. Any policy in the networking area that specifically lists the IP that is to be removed, will cause these types of error messages.

 

I'll try it again either this evening or this weekend. Also -- how would this affect the certificate I created on the smoothwall? Would it remove the IP and then re-add it once the interface is created or would I have to recreate the whole certificate?

Posted
The certificate should have no play in this - hostname and IP stays the same correct?

 

Yes after I recreate it the IP and hostname will be the same.

 

I wish I had a second one of these things so I could figure this stuff out without messing with my production unit.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...