Aldmi Posted October 19, 2023 Posted October 19, 2023 Had a smoothwall S9+ installed over the summer and not had any major issues until a couple of weeks ago Randomly one day all users either wired or on the wifi couldn't get onto random sites or took ages to load and both getting the error message conenctions timeout. I rebooted the firewall and that seemed to fix it and logged it with Smoothwall. They said because I rebooted they couldn't see the cause! Tuesday morning same thing happened again and I logged a high prioity support ticket, The only update i've had since then is that its been passed to second line support. It causing major issues here as we can't access iSAMS, office 365 and some online exams had to be cancelled today. I've added a few staff as exceptions and theirs are working fine. I'm new to smoothwall so not sure if there is anything I can do other then keep chasing the support for an update. I've run the Functionality test and atatched the results if anyone has any ideas on anythign I can try
robintech Posted October 19, 2023 Posted October 19, 2023 (edited) Does it show anything on the real time Reports, Realtime, Webfilter IPaddress:441/modules/guardian3/cgi-bin/reports/guardian_logviewer.cgi?realtime=1 It has an export log function for the various logs or just browsing them looking for something that stands out might help, not sure how it gets wiped on a reboot, ours says a month but might be something in memory Reports, Logs, System etc IPaddress:441/cgi-bin/log/system.dat Edit: When they can't reach the internet do they get a block page or just timeout, I'd check if the computer can ping the Firewall IP and what it thinks the ARP address of the firewall interface is , could be something else on the same IP intermittently? Edited October 19, 2023 by ittech2342323
ITGuyNW Posted October 19, 2023 Posted October 19, 2023 Cant say I'm impressed with their support. Kits alright once its up and running though.
Aldmi Posted October 19, 2023 Author Posted October 19, 2023 Cant say I'm impressed with their support. Kits alright once its up and running though. I'm really dissapointed as well, we had Fortinet for 8 years and one of the reasons we moved is because Smoothwall said as they are UK passed and understood schools we would get much better support
DGardiner Posted October 19, 2023 Posted October 19, 2023 (edited) hows your dns configured? in network settings advanced what is your syn backlog/arp table size set to? i remember having to adjust one of these a few years back for similar reasons Edited October 19, 2023 by DGardiner
timbo343 Posted October 19, 2023 Posted October 19, 2023 hows your dns configured? in network settings advanced what is your syn backlog/arp table size set to? i remember having to adjust one of these a few years back for similar reasonsI second this, check the ARP table size in Network > Settings > Advanced. Remember that the ARP table will have EVERYTHING in it from APs to Switches, desktops / laptops to Servers. I've recently expanded mine to 8192.
Aldmi Posted October 19, 2023 Author Posted October 19, 2023 I second this, check the ARP table size in Network > Settings > Advanced. Remember that the ARP table will have EVERYTHING in it from APs to Switches, desktops / laptops to Servers. I've recently expanded mine to 8192. ARP Table size is 16384 and SYN backlog queue size is 65536 I've just rung and said the head is close to making an official complaint and it is now been escalated so hopefully get something sorted
timbo343 Posted October 19, 2023 Posted October 19, 2023 ARP Table size is 16384 and SYN backlog queue size is 65536 I've just rung and said the head is close to making an official complaint and it is now been escalated so hopefully get something sorted Will tag a few smoothwall people in this who might be able to help. @tom_newton @ibpalle @matt_shakespeare
timbo343 Posted October 19, 2023 Posted October 19, 2023 What happens if you put those URLs in Auth Bypass and then make sure Auth Bypass is listed in Web Proxy > Authentication > Exceptions? What release of the UI are you using? Do you know about port 801 for proxy which allows you to list specific IP addresses that you can use with port 801 rather than 8080?
DGardiner Posted October 19, 2023 Posted October 19, 2023 ARP Table size is 16384 and SYN backlog queue size is 65536 I've just rung and said the head is close to making an official complaint and it is now been escalated so hopefully get something sorted how about your dns? are you using the internal dns, forwarding external to a decent provider? google/cloudflare then setting up your conditionals for the internal domains? the facct your external dns isnt workign but internal is would have me ast somethings a miss there, maybee a bad isp dns server? or you sending stuff back internal to external lookups
timbo343 Posted October 19, 2023 Posted October 19, 2023 Can you post a screen shot of your DNS page?
Aldmi Posted October 19, 2023 Author Posted October 19, 2023 Can you post a screen shot of your DNS page? domain has our internal domain there but hidden it
Netwacky87 Posted October 19, 2023 Posted October 19, 2023 This is going to sound like the most bizare post to help but bear with me. I had a similar issue with Smoothwall where anything in exceptions would work fine but other things would time out or give errors. Randomly, I readjusted the Authentication policies in Web Proxy > Authentication > Transparent Authentication Policies and just move them around, click Save (and move them back if required and press Save again) This kicked everything into life - Honestly, so strange but worked for us.
timbo343 Posted October 19, 2023 Posted October 19, 2023 We have our DNS set up like this: Windows DNS (under Forwarders tab) points to the Smoothwall and to other DNS hosts, with Smoothwall being at the top of the list. Then on the Smoothwall DNS page: Use System Internal DNS Server DNS forwarders: 8.8.8.8 | All available Conditional Forwarders: Server IP - you DNS servers Domains. The "in-addr.arpa" addresses from your windows DNS and your local Domain suffix.
timbo343 Posted October 19, 2023 Posted October 19, 2023 (edited) [ATTACH=CONFIG]70126[/ATTACH] domain has our internal domain there but hidden it Change your conditional DNS forwarders. Here is an example: Also as a test set the User Defined option on the DNS page to one of your windows DNS servers, just for testing at the moment. Edited October 19, 2023 by timbo343
DGardiner Posted October 19, 2023 Posted October 19, 2023 presumably thats your ISP dns, bin it and fire it all at google, may need to reboot to unupset whatevers broken
ibpalle Posted October 19, 2023 Posted October 19, 2023 (edited) A couple of log entries from the web filter might be useful. Also, run the functionality test for basic connectivity in system - diagnostics - functionality tests. Any obvious issues there? Is there a difference between web traffic and non-web traffic? I am assuming you have an AD and clients are using your AD DNS servers? What are the AD servers using - root hints or forwarders in DNS? If forwarders, then which ones? Edited October 19, 2023 by ibpalle
Aldmi Posted October 20, 2023 Author Posted October 20, 2023 Thanks for the advice everyone, had the remote support session and touchwood it is now working. Looks like it was a combination of the advice you all gave: the issue here looks to have been a combination of bad cached info and DNS throttling. I added in additional DNS servers to avoid the DNS issues and also cleared the DNS cache. Also, I cleared the Guardian caches and then disabled them so that the HTTPS and Proxy caches will no longer cause problems. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now