timbo343 Posted February 28, 2025 Posted February 28, 2025 I've set up a Site to Site IPSEC VPN and the both Smoothwall boxes are talking, however how do i get traffic from School A to School B?
speakercon Posted February 28, 2025 Posted February 28, 2025 I'm not a smoothwall user but I imagine you'll need to add the source/destination into the firewall rules and static routes, if you haven't already?
timbo343 Posted February 28, 2025 Author Posted February 28, 2025 Checked and checked and checked. Still doesnt work. I've had 4 / 5 of us look over it. I'm hopkgn someone at Smoothwall will see this and help.
Jonah Posted February 28, 2025 Posted February 28, 2025 You also need a firewall rule to allow the IPSec interface to pass traffic to your internal LAN interface(s)
timbo343 Posted February 28, 2025 Author Posted February 28, 2025 (edited) You also need a firewall rule to allow the IPSec interface to pass traffic to your internal LAN interface(s)Yup got that set. I can see each of the smoothwalls ping switches on the other network but i cannot get devices to ping devices from either side. Looking at all the old guides online it looks so easy to setup yet typically for me it's not. Part of me is thinking Subnets under Network > Routing needs setting up but this doesnt make any difference either. Edited February 28, 2025 by timbo343
PaddyNewman Posted February 28, 2025 Posted February 28, 2025 You need routes to point the remote subnets towards your smoothwalls IPsec interface IP/VPN IP? If the VPN is up, traffic just needs to be sent to that gateway, I would expect that to be part of the IPsec setup though... This might be within your local network though. Traceroute to an endpoint at the other site, where does it stop/die. I've had multiple smoothwalls installs absorb 10.x ranges. I'm sure it's been down to dodgy customer config but we've had traffic enter but not return as it's been routed badly at the remote end.
timbo343 Posted February 28, 2025 Author Posted February 28, 2025 You need routes to point the remote subnets towards your smoothwalls IPsec interface IP/VPN IP? If the VPN is up, traffic just needs to be sent to that gateway, I would expect that to be part of the IPsec setup though... This might be within your local network though. Traceroute to an endpoint at the other site, where does it stop/die. I've had multiple smoothwalls installs absorb 10.x ranges. I'm sure it's been down to dodgy customer config but we've had traffic enter but not return as it's been routed badly at the remote end.Traceroot on a device hits the smoothwall at the first hop and stops. I think i've got the subnets setup correctly. In terms of the "Gateway", is this the external IP of the smoothwall or the gateway IP of the network? What every i try it doesn't work.
PaddyNewman Posted March 1, 2025 Posted March 1, 2025 Smoothwall as your gateway, or Smoothwall as the IPsec gateway? I'll have to nose over how mines set up, not on a SW but it'll be the same. My layer3 points that range towards my VPN gateway address from what I remember. If you are getting to the VPN gateway, I'd say it the return end personally, or just one of the devices taking full ownership of the subnet and not sending return traffic back.
timbo343 Posted March 1, 2025 Author Posted March 1, 2025 Smoothwall as your gateway, or Smoothwall as the IPsec gateway? I'll have to nose over how mines set up, not on a SW but it'll be the same. My layer3 points that range towards my VPN gateway address from what I remember. If you are getting to the VPN gateway, I'd say it the return end personally, or just one of the devices taking full ownership of the subnet and not sending return traffic back.In the Subnet page of Smoothwall it says Network, Subnet, Gateway. I'm presuming Gateway is the IP address of the remote Smoothwall device for that network. Site A Network: 172.16.24.0 Subnet: 255.255.248.0 Smoothwall: 172.16.24.8 Site B Network: 172.25.160.254 Subnet: 255.255.248.0 Smoothwall: 172.25.160.254 Must admit, i wish Smoothwall gave some diagrams as examples in their documentation.
Jonah Posted March 1, 2025 Posted March 1, 2025 (edited) In the Subnet page of Smoothwall it says Network, Subnet, Gateway. I'm presuming Gateway is the IP address of the remote Smoothwall device for that network. Site A Network: 172.16.24.0 Subnet: 255.255.248.0 Smoothwall: 172.16.24.8 Site B Network: 172.25.160.254 Subnet: 255.255.248.0 Smoothwall: 172.25.160.254 Must admit, i wish Smoothwall gave some diagrams as examples in their documentation. Does your Smoothwall do your routing, or does a core switch? Our default route out for the core switches is the SW IP. Our setup for two sites is: Site A (10.0.0.0/16) - Smoothwall IP 10.0.5.254, Smoothwall VLAN/Core Switch interface IP: 10.0.5.1 Subnet settings: Network: 10.0.0.0 Subnet: 255.255.0.0 Gateway: 10.0.5.1 IP Sec settings: Local IP: Local Network: 10.0.0.0/16 Remote IP: Remote Network: 10.10.0.0/16 Site B (10.10.0.0/16) - Smoothwall IP 10.10.5.254, Smoothwall VLAN/Core Switch interface IP: 10.10.5.1 Subnet settings: Network: 10.10.0.0 Subnet: 255.255.0.0 Gateway: 10.10.5.1 IP Sec settings: Local IP: Local Network: 10.10.0.0/16 Remote IP: Remote Network: 10.0.0.0/16 Edited March 1, 2025 by Jonah 1
timbo343 Posted March 1, 2025 Author Posted March 1, 2025 (edited) Does your Smoothwall do your routing, or does a core switch? Our default route out for the core switches is the SW IP. Our setup for two sites is: Site A (10.0.0.0/16) - Smoothwall IP 10.0.5.254, Smoothwall VLAN/Core Switch interface IP: 10.0.5.1 Subnet settings: Network: 10.0.0.0 Subnet: 255.255.0.0 Gateway: 10.0.5.1 IP Sec settings: Local IP: Local Network: 10.0.0.0/16 Remote IP: Remote Network: 10.10.0.0/16 Site B (10.10.0.0/16) - Smoothwall IP 10.10.5.254, Smoothwall VLAN/Core Switch interface IP: 10.10.5.1 Subnet settings: Network: 10.10.0.0 Subnet: 255.255.0.0 Gateway: 10.10.5.1 IP Sec settings: Local IP: Local Network: 10.10.0.0/16 Remote IP: Remote Network: 10.0.0.0/16 By following this I've managed to lock myself out to the network via SSL VPN trying access the Smoothwall and the Network - long story but.. if anyone knows how add Smoothwall Access on ports 81 and 441 to an existing Smoothwall Access rule via SSH or CLi, please pipe up otherwise it means a full restore from backup. Anyway i put the following into my (SiteA) Smoothwall Subnet page and it broke clients being able to communicate internally with the smoothwall at 172.16.24.8. The same happened at SiteB with the smoothwall at 172.22.192.2 (different site to the one earlier in the topic). Site A (172.16.24.0/21) - Smoothwall IP 172.16.24.8, Smoothwall VLAN/Core Switch interface IP: 172.16 24.24 The Core switch has a line "ip route 0.0.0.0 0.0.0.0 172.16.24.8" Smoothwall Subnet page settings: Network: 172.16.24.0 Subnet: 255.255.248.0 Gateway: 172.16.24.8 IP Sec settings: Local IP: Local Network: 172.16.24.0/21 Remote IP: Remote Network: 172.22.192.0/21 - - - - - - - - - - - Site B (172.22.192.0/21) - Smoothwall IP 172.22.192.2, Smoothwall VLAN/Core Switch interface IP: 172.22.192.10 Site B has an Aruba 2930 with no IP ROUTE line listed. Smoothwall Subnet page settings: Network: 172.22.192.0 Subnet: 255.255.248.0 Gateway: 172.22.192.10 IP Sec settings: Local IP: Local Network: 172.22.192.0/21 Remote IP: Remote Network: 172.16.24.0/21 Edited March 1, 2025 by timbo343
CrootUK Posted March 2, 2025 Posted March 2, 2025 When on the cli type setup, then you have the “permit admin access” option that’ll create a new access rule on your selected interface. Hopefully that works out for you. 1
timbo343 Posted March 2, 2025 Author Posted March 2, 2025 When on the cli type setup, then you have the “permit admin access” option that’ll create a new access rule on your selected interface. Hopefully that works out for you.Ah yes, thank you. I've got an old test smoothwall at home and have just run setup at the command prompt and it's brought up a menu > Change Admin password > Change Root password > Hosrname > Keyboard layout > Network Interfaces > Permit Admin Access > Restore Configuaration > Serial Console Permit Admin access gives the option for > All internal interfaces > All external interfaces Hope isnt lost just yet, just need to physically get to the box and plug in with a keyboard. I've got ways i can get to the UI via the other VLANs on site 🤞🏻
timbo343 Posted March 2, 2025 Author Posted March 2, 2025 Managed to get back into the Smoothwall and remove the subnet tables / lines that i added. Will have a look in detail at this tomorrow. 1
ibpalle Posted March 3, 2025 Posted March 3, 2025 If the Smoothwalls could talk to each other but not the subnets, the most likely cause is routing seen from the clients side. Is the Smoothwall the gateway for the remote subnets? If you had another solution for VPN before, there may be a static route in place? The firewall policy should be LAN and IPSEC in both incoming and outgoing interface. As for Smoothwall access over SSL and VPN, make sure there is an access policy for the SSL VPN and IPSEC interface in Smoothwall access. 1
timbo343 Posted March 3, 2025 Author Posted March 3, 2025 That's the network layouts that we want to get talking.
ibpalle Posted March 3, 2025 Posted March 3, 2025 Should be simple enough - all routes are added by the VPN engine so you don't need any additional ones adding. Firewall policies are the only ones that need to be added manually. Have you added and policies in the SNAT and LLB policies section? Make sure the policy for traffic to internal networks is at the top of that list.
timbo343 Posted March 3, 2025 Author Posted March 3, 2025 Should be simple enough - all routes are added by the VPN engine so you don't need any additional ones adding. Firewall policies are the only ones that need to be added manually. Have you added and policies in the SNAT and LLB policies section? Make sure the policy for traffic to internal networks is at the top of that list. Oh hang on. That rule: Source IP: Any Destination IP: Internal Networks Service: Any SNAT: X LLB Pool / Gateway: Automatic Enabled: Tick Needs to be at the top of the list?? It was at the bottom on smoothwall 172.16.24.8 - that could be the issue??
ibpalle Posted March 3, 2025 Posted March 3, 2025 Yes - if there are policies that affects that traffic before the internal networks policy then the traffic wouldn't be sent via the ipsec tunnel. That would explain you seeing traffic going to the Smoothwalls but no further. It gets shunted out via the external gateway and disappears forever...lost...alone... 1
timbo343 Posted March 3, 2025 Author Posted March 3, 2025 If the Smoothwalls could talk to each other but not the subnets, the most likely cause is routing seen from the clients side. Is the Smoothwall the gateway for the remote subnets? If you had another solution for VPN before, there may be a static route in place? The firewall policy should be LAN and IPSEC in both incoming and outgoing interface. As for Smoothwall access over SSL and VPN, make sure there is an access policy for the SSL VPN and IPSEC interface in Smoothwall access. Thank you so much!!! Got it working. 3
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now