TechMonkey Posted April 9, 2024 Posted April 9, 2024 I seem to have a silly issue. I'm starting to set up Firewall rules on Smoothwall and taking it slowly to ensure I don't do anything silly. I am turning logging on to check the rule and see what it catches, but I am getting no logs at all. Even the default rule is set to log at the moment and still a big empty. Is there something really obvious I am missing like an ON button for the firewall? I have a support call open but so far 2 weeks and all I have had is a request to update to the latest version and an escalation.
robintech Posted April 9, 2024 Posted April 9, 2024 Has it got Realtime selected at the top left (which should change to Pause) , timeframe might be before you starting setting it up 1
TechMonkey Posted April 9, 2024 Author Posted April 9, 2024 Yep, had it running for a good month now and it had some rules previously. Never seen an absolutely blank log, so I'm guessing it is something technically gone TU, just thought I'd check my sanity! Back to waiting for 2nd line
ibpalle Posted April 9, 2024 Posted April 9, 2024 You can enable auditing of traffic is the network - settings - advanced to see all traffic going to, from or through the Smoothwall system. Is this Smoothwall a firewall or a bridge deployment? 1
TechMonkey Posted April 9, 2024 Author Posted April 9, 2024 Even with those tick boxes set, no results coming in the log. I have to be honest, not sure. I would have said firewall but would be guessing. Nothing is set in the bridging options.
ibpalle Posted April 9, 2024 Posted April 9, 2024 (edited) Check in network - configuration - interfaces. If the role listed for the interface the proxy is configured on is 'Bridge' then firewall policies won't have any effect. Is the Smoothwall your firewall as well as filter or do you have another firewall? Edited April 9, 2024 by ibpalle 1
TechMonkey Posted April 9, 2024 Author Posted April 9, 2024 Nope, no Bridge members. It used to be the firewall, in days gone past. A separate device was setup, but we are now looking at moving back to Smoothwall as an all-in-one device to simplify things.
ibpalle Posted April 9, 2024 Posted April 9, 2024 If the smoothwall is not the firewall only web traffic will be seen on the smoothwall - no firewall policies will apply. Either Smoothwall is being used as a non-transparent proxy or as a fake gateway and transparent proxy - in either case, no firewall policies are likely to apply.
TechMonkey Posted April 10, 2024 Author Posted April 10, 2024 Thanks ibpalle. So is there a way to turn the firewall on? Or is it down to how the traffic is being routed through the Smoothwall? Currently all traffic is routed through the Smoothwall as it is set as the Gateway of the core switch.
ibpalle Posted April 10, 2024 Posted April 10, 2024 Yes, setup an interface with the external role and you ISP internet connection details. I'd suggest you talk with your account manager and have them setup a rework session to reconfigure the Smoothwal. 1
TechMonkey Posted April 10, 2024 Author Posted April 10, 2024 Thanks again ibpalle. I'll wait for the ticket to get picked up, we have an external role setup on an interface so I think there must be something further under the hood.
TechMonkey Posted April 11, 2024 Author Posted April 11, 2024 For future adventurers, it was a unique under the hood issue. Somehow, somewhen, the files and folder structure associated with the firewall logs had been deleted, leaving nowhere for it to be written to or display from. Engineer kindly rebuilt the structure by hand and we are up and running! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now