jnfarmer Posted February 6, 2025 Posted February 6, 2025 Hi all Anyone have the Smoothwall appliane as a VM on VMware? Smoothwall have recommended installing in bridge mode, but I am getting tied up in knots for what port groups I need to use and whether I should use permiscuous mode. Gateway is up on just a single basic interface, and can ping internal/external, but as soon I change it in to bridge mode, nada, kaput, can't do nowt! Cheers James
Davit2005 Posted February 6, 2025 Posted February 6, 2025 Mostly you will need to enable promiscous mode to get these to work however that is a security risk and as I assume the WAN connection would be external. Not generally recommended to run firewall on VM TBH although many do including myself at one stage but only in a home environment.
jnfarmer Posted February 6, 2025 Author Posted February 6, 2025 Thanks, to clarify, not running it as a firewall, just the web filter for BYOD and Guest devices. All managed devices will use cloud filter. Would it be promiscuous mode on both port groups, or just the one the VM is actually in?
ibpalle Posted February 7, 2025 Posted February 7, 2025 Running as a VM is definitely possible - we try to avoid complext network configurations like bridges on VM installs but otherwise they are fine. Only caveat is the disk subsystem. Smoothwall logs a lot and if the disk subsystem is shared by many VMs the disk IO may cause issues.
jnfarmer Posted February 7, 2025 Author Posted February 7, 2025 Running as a VM is definitely possible - we try to avoid complext network configurations like bridges on VM installs but otherwise they are fine. Only caveat is the disk subsystem. Smoothwall logs a lot and if the disk subsystem is shared by many VMs the disk IO may cause issues. Oh, well the bridged VM suggestion came from Smoothwall. How else would we do this on a VM?
ibpalle Posted February 7, 2025 Posted February 7, 2025 We try to avoid - not rule it out by default. An alternative to a bridge is using a single NIC smoothwall as gateway, the Smoothwall will intercept web traffic and forward all other traffic to the 'real' gateway. Policy based routing can be used as well.
jnfarmer Posted February 7, 2025 Author Posted February 7, 2025 We try to avoid - not rule it out by default. An alternative to a bridge is using a single NIC smoothwall as gateway, the Smoothwall will intercept web traffic and forward all other traffic to the 'real' gateway. Policy based routing can be used as well. Just spoken to some of your colleagues and looks like we are going to go with setting the Smoothwall as the DG in our DHCP scopes.
Arclin Posted March 5, 2025 Posted March 5, 2025 We've run our Smoothwall as a VM for years, as you say it's only for the filtering, it's been fine. 1
jnfarmer Posted March 5, 2025 Author Posted March 5, 2025 Thanks all. We're all good now. Just need to work out how to kill Safari using Intune. Giving me the run around a bit...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now