Sheridan Posted November 8, 2021 Posted November 8, 2021 I don't think Smoothwall actually respond to support requests these days, so hopefully someone here may be able to help! We have a port forward rule to an internal address, 10.x.x.x - this rule works fine and the service (SIP) is also working fine. However, when looking at the firewall logs, there is never an entry for the 10.x.x.x address outbound, even though there is an outbound rule allowing it, and also set to log traffic. Its odd because its working as expected and it must be going outbound, but I can't see the traffic in the firewall logs. I've checked the other rules and its the one rule it would hit a match on so I'm confused as to why it never appears?
TechMonkey Posted November 8, 2021 Posted November 8, 2021 I don't think Smoothwall actually respond to support requests these days, so hopefully someone here may be able to help! We have a port forward rule to an internal address, 10.x.x.x - this rule works fine and the service (SIP) is also working fine. However, when looking at the firewall logs, there is never an entry for the 10.x.x.x address outbound, even though there is an outbound rule allowing it, and also set to log traffic. Its odd because its working as expected and it must be going outbound, but I can't see the traffic in the firewall logs. I've checked the other rules and its the one rule it would hit a match on so I'm confused as to why it never appears? Worth raising the entry to the top to ensure it isn't being allowed in a different rule? Is there a different way to look for the rule? By port say?
Sheridan Posted November 8, 2021 Author Posted November 8, 2021 (edited) Worth raising the entry to the top to ensure it isn't being allowed in a different rule? Is there a different way to look for the rule? By port say? It weird, because even by port it doesn't appear in the log (apart from the Port Forward rule logs) - but the secondary address used for voice data does show correctly. Its got me baffled! Edited November 8, 2021 by Sheridan
TechMonkey Posted November 8, 2021 Posted November 8, 2021 At a guess I would say a rule higher up is taking priority but not logging. Is it worth turning on all logging and trying? Also, not wanting to teacher your granny to suck citrus, but are you sure the system is working as expected? Maybe the secondary has taken priority?
Sheridan Posted November 8, 2021 Author Posted November 8, 2021 I created a rule, and put it at the top of the list to allow all outbound traffic from that ip and also log it - still nothing shows in the logs. I know the ip is connecting because the phone engineer showed me the logs for their system showing a connection from the internal ip connecting out to their system. Very bizarre, but smoothwall logging has always been a bit unreliable in my opinion.
TechMonkey Posted November 8, 2021 Posted November 8, 2021 I wonder if SIP calls aren't logged for some reason? I've just turned the logging on for our VOIP server and dialled out and get nothing, even selecting the rule. Interesting.
Sheridan Posted November 8, 2021 Author Posted November 8, 2021 I wonder if SIP calls aren't logged for some reason? I've just turned the logging on for our VOIP server and dialled out and get nothing, even selecting the rule. Interesting. Weird eh? But I do see traffic from the ip that handles the voice data, just not the main ip that handles the initial SIP connections - but the port forwards to this ip do get logged
TechMonkey Posted November 8, 2021 Posted November 8, 2021 (edited) To update my testing, I had to turn publishing on for the rule that contacts our SIP provider. I'll try your example rule and see if that catches anything. EDIT: You may have to wait for Smoothwall to get in touch unfortunately. Mine shows logged traffic from that server with a rule saying source IP as the server's IP and everything else as "ANY". Edited November 8, 2021 by TechMonkey
tom_newton Posted November 8, 2021 Posted November 8, 2021 SIP proxy? And have you submitted a ticket? I'd be surprised if there was a big delay - our ticket numbers have been a LOT better this year than last (not that there isn't still progress to be made)
Sheridan Posted November 8, 2021 Author Posted November 8, 2021 SIP Proxy isn't used, we did raise a ticket but to be honest we had a bigger problem last week and still haven't had a response on that ticket either, which meant I simply had to roll the most recent update back to fix our problem
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now