maxpitkin26 Posted November 1, 2023 Posted November 1, 2023 God damn I've been going through the works with this one. I'll try to keep this short but with vital information. We use Smoothwall as our filtering. We also have LGFL as our ISP. We have a few IP address ranges. One IP address range works, the other one does and doesn't at the same time. It's driving me crazy. So I'm going to reference A: good IP range, B: bad IP range. A IP range goes through Smoothwall and allows/blocks what we want B IP range goes through our Smoothwall and allows/blocks SOME of what we want B IP range has been fiddled with to get this working - I've been ensuring transparent/none transparent is working well, Have tried application and computer based proxy settings (manual/auto and even setting 801 as the port so it's unfiltered) Messing with exemptions but nothing as worked so far What's even stranger - A IP range can ping Google DNS. B range IP address cannot. Doing a tracert to Google's DNS stops at our gateway. Which is the same Gateway to our Smoothwall as the Good IP address range. They stil have internet and is still filtered by Smoothwall! I've been in contact and they are stating it might not be them on this one. Would be happy if anyone can give some insight!
ibpalle Posted November 2, 2023 Posted November 2, 2023 Web traffic is handled by the proxy and non web traffic is handled by the firewall. It sounds like the firewall policies are blocking outgoing traffic that is not web traffic. Have a look at the reports - realtime - firewall while trying to get to the internet from the non working range and see if there are any blocks.
Mako Posted November 2, 2023 Posted November 2, 2023 Have you recently changed to/from these IP ranges? Try and do things (ping Google, browse the web etc) and look at the live Firewall logs - ensure you have logging enabled on all the rules. You should be able to catch what's going on. I've had it on a remote site where we changed IP range and the Smoothwall was sometimes seeing the devices as external and blocking them on the default external rule, i.e dropping the request.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now