mikkydoos Posted March 20, 2024 Posted March 20, 2024 Hi all, Got a query on why something is happening... this has to be DNS??? Created VLAN's on an internal interface in Smoothwall. Everything working fine. Packets are going to and from where should, routing is tested and fine. L3 is switch doing the LAN routing & gateways for the VLANs. Next hop address is Smoothwall. VLAN 1 is still currently the main subnet for this network - 10.122.x.x, gateway = Smoothwall. DCs & DNS servers are on this subnet. I've changed the gateway on DC1 to the L3 switch VLAN1 gateway - 10.10.x.1, for the VLAN clients to get DHCP address via the L3 IP helper... all good. Everything connecting everywhere fine. If I change the DC gateway back to Smoothwall, the VLAN clients lose internet immediately but can still ping outside by IP address. Yes this causes loss of connectivity to the DC as Smoothwall can't route the VLANs to the DC but why cant I resolve external domain names ? I'm obviously fouling up the DC's route by changing the gateway but what is trying to get back from the the DC to the VLAN clients to cause loss of connectivity? ????? Cheers in advance
PaddyNewman Posted March 20, 2024 Posted March 20, 2024 I'm no smoothwall expert but I've had more than 1 instance of Smoothwall absorbing all private addressing, assuming you have a static route of your LAN to the L3 switch? 1
Davit2005 Posted March 21, 2024 Posted March 21, 2024 (edited) I assume you have put a route on the Smoothwall to route traffic destined to the 10.10.x.1 network via the ip address of the layer 3 switch as the DC works when it's gateway is the layer 3 switch. Does sound possibly like some sort of routing issue. The clients on the 10.10.x.1 network are they able to ping the DC when the DC has it's gateway on the Smoothwall. Is the DC able to resolve DNS queries or ping external IP addresses i.e. 8.8.8.8 try using NSLOOKUP on the DC and specify an external server and see if it resolves DNS. Edited March 21, 2024 by Davit2005 1
synaesthesia Posted March 21, 2024 Posted March 21, 2024 One thing I've fallen foul of recently is the odd way smoothwall handles vlans - so if you have a default vlan of 1 and other vlans added via a trunk port other than whichever is dealing vlan 1, you need to add vlan 1 with IP to the trunk port too. 1
mikkydoos Posted March 21, 2024 Author Posted March 21, 2024 (edited) @Davit2005 I assume you have put a route on the Smoothwall to route traffic destined to the 10.10.x.1 network via the ip address of the layer 3 switch as the DC works when it's gateway is the layer 3 switch. & @synaesthesia --- I did put a route into Network/Subnets for VLAN 1 -- still no connectivity --- Also defined VLAN1 in Network/Interfaces on the adapter carrying the VLANs - no effect. --- There is a route missing somewhere but I can't find where -- the DC is the authoritive DNS server on the network so I think the issue is that the forwarders (8.8.8.8 etc) get out but the DC can't find a route back to the other VLANs. The clients on the 10.10.x.1 network are they able to ping the DC when the DC has it's gateway on the Smoothwall. Is the DC able to resolve DNS queries or ping external IP addresses i.e. 8.8.8.8 try using NSLOOKUP on the DC and specify an external server and see if it resolves DNS. --- No. Can't ping the DC when the DC gateway is Smoothwall. Edited March 21, 2024 by mikkydoos
Davit2005 Posted March 21, 2024 Posted March 21, 2024 (edited) @Davit2005 & @synaesthesia --- I did put a route into Network/Subnets for VLAN 1 -- still no connectivity --- Also defined VLAN1 in Network/Interfaces on the adapter carrying the VLANs - no effect. --- There is a route missing somewhere but I can't find where -- the DC is the authoritive DNS server on the network so I think the issue is that the forwarders (8.8.8.8 etc) get out but the DC can't find a route back to the other VLANs. The clients on the 10.10.x.1 network are they able to ping the DC when the DC has it's gateway on the Smoothwall. Is the DC able to resolve DNS queries or ping external IP addresses i.e. 8.8.8.8 try using NSLOOKUP on the DC and specify an external server and see if it resolves DNS. --- No. Can't ping the DC when the DC gateway is Smoothwall. Could be ping is blocked on the smoothwall. For that matter is DNS allowed between the two interfaces on the smoothwall? Confessing not knowing much about the smoothwall but is return (established) traffic allowed by default Edited March 21, 2024 by Davit2005
timbo343 Posted March 21, 2024 Posted March 21, 2024 One thing I've fallen foul of recently is the odd way smoothwall handles vlans - so if you have a default vlan of 1 and other vlans added via a trunk port other than whichever is dealing vlan 1, you need to add vlan 1 with IP to the trunk port too.This caught me out on the blue S2/S4/S8 boxes. The Teal boxes S3/S5/S9 don't have this problem.
mikkydoos Posted March 22, 2024 Author Posted March 22, 2024 This caught me out on the blue S2/S4/S8 boxes. The Teal boxes S3/S5/S9 don't have this problem. Interesting @timbo. This is an S14. What IP?... the VLAN1 gateway I'm using now ??
synaesthesia Posted March 22, 2024 Posted March 22, 2024 This caught me out on the blue S2/S4/S8 boxes. The Teal boxes S3/S5/S9 don't have this problem. Ours is a teal S9 :/
timbo343 Posted March 22, 2024 Posted March 22, 2024 We have our smoothwall boxes set up so they are doing the Layer 3 routing, so VLAN 1 (the main network) is only on port 1 (first port on the smoothwall) and the VLANs (about 5 of them) are all on port 2 (second port on the smoothwall). The switches are only configured so that the ports are members of each VLAN the smoothwall provides the gateways. From what i understand this isn't how the OP networks are not setup but thought i'd add how we have our networks at 11 schools setup.
CrootUK Posted February 17 Posted February 17 On 21/03/2024 at 08:15, synaesthesia said: One thing I've fallen foul of recently is the odd way smoothwall handles vlans - so if you have a default vlan of 1 and other vlans added via a trunk port other than whichever is dealing vlan 1, you need to add vlan 1 with IP to the trunk port too. Could you PM me what you mean here please? I got a feeling I am suffering this issue right now. single port, two vlans untagged (vlan1) and tagged vlan 10. seems to be working but the firewall rules dont seem to apply when specifying "All internal networks" or the VLAN interface "VLAN1" Thank you
synaesthesia Posted February 18 Posted February 18 I'll have to get back to you on this - since updating to Maiden 33 last night, our setup has completely failed As Smoothwall is the only thing that has updated, I've reached out to them for urgent support.
tom_newton Posted February 18 Posted February 18 Sorry to hear that - updates do occasionally go awry, although maiden is our most used version, and has been pretty smooth, it's no fun at all when you get caught by something like that. Can you let me know your ticket so I can follow the progress?
synaesthesia Posted February 18 Posted February 18 Just got off the phone to Smoothwall - Maiden 33 has a bug which only affects people still using the default vlan of 1 which may also be affecting you if you're struggling. Roll back to 32 and you should be golden They're working on a fix for Maiden 34.
synaesthesia Posted February 18 Posted February 18 1 minute ago, tom_newton said: Sorry to hear that - updates do occasionally go awry, although maiden is our most used version, and has been pretty smooth, it's no fun at all when you get caught by something like that. Can you let me know your ticket so I can follow the progress? Jinx! That was ticket #650256 - looks like all is in hand, I'm going to restore to 32 in 10 minutes. Been holding off our vlan changes until Summer when we'll be removing 1 entirely (at last!)
tom_newton Posted February 18 Posted February 18 Ah, I see there is a vlan bug in 33, I wasn't sure if that was the case, so hopefully a revert will sort it. I'll do a bit of digging when I speak to the product manager for on prem this afternoon 1
CrootUK Posted February 18 Posted February 18 (edited) I ended up doing tagged vlan1 bewteen switch and smoothwall and blackholing the native vlan switch side, seems to be working ok now on 33. Edited February 18 by CrootUK
tom_newton Posted February 19 Posted February 19 I'm told this issue should be resolved in 34 - caught us a little by surprise after ~80% of customers on 33 we found a few wlth this issue in the last week or so.
tom_newton Posted February 26 Posted February 26 Going out to the second wave of customers today - usually we go internal staff testing, wave 1, wave 2, everyone. If you want to DM me I can get you on earlier for just this release 1
CrootUK Posted February 28 Posted February 28 On 26/02/2026 at 09:03, tom_newton said: Going out to the second wave of customers today - usually we go internal staff testing, wave 1, wave 2, everyone. If you want to DM me I can get you on earlier for just this release Cheers Tom, showing for us now. Probably update next weekend. 1
KSCSIT Posted March 16 Posted March 16 2 minutes ago, CrootUK said: Did Maiden-34 get pulled? Noticed this as well, had it down to install over Easter.... 1
mikkydoos Posted March 16 Author Posted March 16 I'm getting odd ICMP packet drops on VLAN1 from our L3 core switches. I wonder if Maiden 33 is the problem. I wish I could turn off the routing in Smoothwall and just let our real routers do the work. Its a pain.
tom_newton Posted March 16 Posted March 16 Yes, 34 was paused as we found a couple of issues, it will be back shortly
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now