Jump to content

Recommended Posts

Posted

Had a smoothwall S9+ installed over the summer and not had any major issues until a couple of weeks ago

 

Randomly one day all users either wired or on the wifi couldn't get onto random sites or took ages to load and both getting the error message conenctions timeout. I rebooted the firewall and that seemed to fix it and logged it with Smoothwall. They said because I rebooted they couldn't see the cause!

 

Tuesday morning same thing happened again and I logged a high prioity support ticket, The only update i've had since then is that its been passed to second line support. It causing major issues here as we can't access iSAMS, office 365 and some online exams had to be cancelled today. I've added a few staff as exceptions and theirs are working fine.

 

I'm new to smoothwall so not sure if there is anything I can do other then keep chasing the support for an update. I've run the Functionality test and atatched the results if anyone has any ideas on anythign I can try

2.JPG

1.JPG

Posted (edited)

Does it show anything on the real time Reports, Realtime, Webfilter

IPaddress:441/modules/guardian3/cgi-bin/reports/guardian_logviewer.cgi?realtime=1

 

It has an export log function for the various logs or just browsing them looking for something that stands out might help, not sure how it gets wiped on a reboot, ours says a month but might be something in memory

Reports, Logs, System etc

IPaddress:441/cgi-bin/log/system.dat

 

 

Edit:

When they can't reach the internet do they get a block page or just timeout, I'd check if the computer can ping the Firewall IP and what it thinks the ARP address of the firewall interface is , could be something else on the same IP intermittently?

Edited by ittech2342323
Posted
Cant say I'm impressed with their support. Kits alright once its up and running though.

 

I'm really dissapointed as well, we had Fortinet for 8 years and one of the reasons we moved is because Smoothwall said as they are UK passed and understood schools we would get much better support

Posted (edited)

hows your dns configured?

 

in network settings advanced what is your syn backlog/arp table size set to? i remember having to adjust one of these a few years back for similar reasons

Edited by DGardiner
Posted
hows your dns configured?

 

in network settings advanced what is your syn backlog/arp table size set to? i remember having to adjust one of these a few years back for similar reasons

I second this, check the ARP table size in Network > Settings > Advanced.

 

Remember that the ARP table will have EVERYTHING in it from APs to Switches, desktops / laptops to Servers.

 

I've recently expanded mine to 8192.

Posted
I second this, check the ARP table size in Network > Settings > Advanced.

Remember that the ARP table will have EVERYTHING in it from APs to Switches, desktops / laptops to Servers.

I've recently expanded mine to 8192.

 

ARP Table size is 16384 and SYN backlog queue size is 65536

 

 

I've just rung and said the head is close to making an official complaint and it is now been escalated so hopefully get something sorted

Posted

What happens if you put those URLs in Auth Bypass and then make sure Auth Bypass is listed in Web Proxy > Authentication > Exceptions?

 

What release of the UI are you using?

 

Do you know about port 801 for proxy which allows you to list specific IP addresses that you can use with port 801 rather than 8080?

Posted
ARP Table size is 16384 and SYN backlog queue size is 65536

 

 

I've just rung and said the head is close to making an official complaint and it is now been escalated so hopefully get something sorted

 

 

how about your dns? are you using the internal dns, forwarding external to a decent provider? google/cloudflare then setting up your conditionals for the internal domains?

 

the facct your external dns isnt workign but internal is would have me ast somethings a miss there, maybee a bad isp dns server? or you sending stuff back internal to external lookups

Posted

This is going to sound like the most bizare post to help but bear with me.

 

I had a similar issue with Smoothwall where anything in exceptions would work fine but other things would time out or give errors.

 

Randomly, I readjusted the Authentication policies in Web Proxy > Authentication > Transparent Authentication Policies and just move them around, click Save (and move them back if required and press Save again)

 

This kicked everything into life - Honestly, so strange but worked for us.

Posted

We have our DNS set up like this:

 

Windows DNS (under Forwarders tab) points to the Smoothwall and to other DNS hosts, with Smoothwall being at the top of the list.

 

Then on the Smoothwall DNS page:

 

Use System Internal DNS Server

 

DNS forwarders:

8.8.8.8 | All available

 

Conditional Forwarders:

Server IP - you DNS servers

Domains. The "in-addr.arpa" addresses from your windows DNS and your local Domain suffix.

Posted (edited)
[ATTACH=CONFIG]70126[/ATTACH]

 

domain has our internal domain there but hidden it

 

Change your conditional DNS forwarders.

 

Here is an example:

 

Smoothwall.png

 

Also as a test set the User Defined option on the DNS page to one of your windows DNS servers, just for testing at the moment.

Edited by timbo343
Posted (edited)

A couple of log entries from the web filter might be useful. Also, run the functionality test for basic connectivity in system - diagnostics - functionality tests. Any obvious issues there?

 

Is there a difference between web traffic and non-web traffic?

 

I am assuming you have an AD and clients are using your AD DNS servers? What are the AD servers using - root hints or forwarders in DNS? If forwarders, then which ones?

Edited by ibpalle
Posted

Thanks for the advice everyone, had the remote support session and touchwood it is now working. Looks like it was a combination of the advice you all gave:

 

 

the issue here looks to have been a combination of bad cached info and DNS throttling.

I added in additional DNS servers to avoid the DNS issues and also cleared the DNS cache.

Also, I cleared the Guardian caches and then disabled them so that the HTTPS and Proxy caches will no longer cause problems.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...