jhl_16 Posted July 3, 2024 Posted July 3, 2024 (edited) Hi, We are considering using Smoothwall Edge extension for filtering. Historically we have always used Smoothwall as a proxy server either setting proxy IP details or WPAD which means traffic doesn’t travel through it as a default route. My concern is using the extension I will need to give each client direct access to the internet, instead of just the proxy server. I’d be interested to hear peoples methods of getting the Smoothwall box in line for the secret knock to work, I’m not keen on involving Smoothwall in the routing process though as I’d like to leave that to the switches. My main concern is if someone unplugs a network port and plugs another unmanaged device in they would effectively have unfiltered internet access. We do not use Smoothwall as a Firewall, only filtering. Thanks Edited July 3, 2024 by jhl_16
Steve21 Posted July 3, 2024 Posted July 3, 2024 Generally it's just ISPRouter->Firewall/Filter->MainCore So anything that goes to the ISPRouter has to go via the firewall/filter, even if it's not filtered via the knock etc Steve
DrCheese Posted July 3, 2024 Posted July 3, 2024 Generally it's just ISPRouter->Firewall/Filter->MainCore So anything that goes to the ISPRouter has to go via the firewall/filter, even if it's not filtered via the knock etc Steve Yeah - You set the filter up so *nothing* can get out to the Internet that doesn't go through it first - Then it doesn't matter if you have the edge extension or not.
Aprice Posted July 3, 2024 Posted July 3, 2024 (edited) We have all ours in line, Core switch handles all inter-VLAN traffic, just using the Smoothie as the default route out to the internet. Only issue we have with the Smoothwall boxes is they all seem to have a habit of locking up every now and again and needing the power cable pulling out and putting in again. Might have a bit more of a look into how the secret knock works, wondering if it's something we can implement into Mikrotik using address lists. Edited July 3, 2024 by Aprice
jhl_16 Posted July 3, 2024 Author Posted July 3, 2024 We have all ours in line, Core switch handles all inter-VLAN traffic, just using the Smoothie as the default route out to the internet. Only issue we have with the Smoothwall boxes is they all seem to have a habit of locking up every now and again and needing the power cable pulling out and putting in again. Might have a bit more of a look into how the secret knock works, wondering if it's something we can implement into Mikrotik using address lists. Is your Smoothwall the Firewall too?
Aprice Posted July 3, 2024 Posted July 3, 2024 Is your Smoothwall the Firewall too? usually, sometimes we would put a Mikrotik or ngfw upstream to act as the firewall.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now