Jump to content

Recommended Posts

Posted (edited)

Hi,

 

We are considering using Smoothwall Edge extension for filtering. Historically we have always used Smoothwall as a proxy server either setting proxy IP details or WPAD which means traffic doesn’t travel through it as a default route.

 

My concern is using the extension I will need to give each client direct access to the internet, instead of just the proxy server.

 

I’d be interested to hear peoples methods of getting the Smoothwall box in line for the secret knock to work, I’m not keen on involving Smoothwall in the routing process though as I’d like to leave that to the switches.

 

My main concern is if someone unplugs a network port and plugs another unmanaged device in they would effectively have unfiltered internet access. We do not use Smoothwall as a Firewall, only filtering.

 

Thanks

Edited by jhl_16
Posted

Generally it's just ISPRouter->Firewall/Filter->MainCore

 

So anything that goes to the ISPRouter has to go via the firewall/filter, even if it's not filtered via the knock etc

 

Steve

Posted
Generally it's just ISPRouter->Firewall/Filter->MainCore

 

So anything that goes to the ISPRouter has to go via the firewall/filter, even if it's not filtered via the knock etc

 

Steve

 

Yeah - You set the filter up so *nothing* can get out to the Internet that doesn't go through it first - Then it doesn't matter if you have the edge extension or not.

Posted (edited)

We have all ours in line, Core switch handles all inter-VLAN traffic, just using the Smoothie as the default route out to the internet.

 

Only issue we have with the Smoothwall boxes is they all seem to have a habit of locking up every now and again and needing the power cable pulling out and putting in again.

 

Might have a bit more of a look into how the secret knock works, wondering if it's something we can implement into Mikrotik using address lists.

Edited by Aprice
Posted
We have all ours in line, Core switch handles all inter-VLAN traffic, just using the Smoothie as the default route out to the internet.

 

Only issue we have with the Smoothwall boxes is they all seem to have a habit of locking up every now and again and needing the power cable pulling out and putting in again.

 

Might have a bit more of a look into how the secret knock works, wondering if it's something we can implement into Mikrotik using address lists.

 

Is your Smoothwall the Firewall too?

Posted
Is your Smoothwall the Firewall too?

 

usually, sometimes we would put a Mikrotik or ngfw upstream to act as the firewall.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...