Jump to content

Recommended Posts

Posted (edited)
You also need a firewall rule to allow the IPSec interface to pass traffic to your internal LAN interface(s)
Yup got that set. I can see each of the smoothwalls ping switches on the other network but i cannot get devices to ping devices from either side.

 

Looking at all the old guides online it looks so easy to setup yet typically for me it's not.

 

Part of me is thinking Subnets under Network > Routing needs setting up but this doesnt make any difference either.

Edited by timbo343
Posted

You need routes to point the remote subnets towards your smoothwalls IPsec interface IP/VPN IP?

 

If the VPN is up, traffic just needs to be sent to that gateway, I would expect that to be part of the IPsec setup though...

This might be within your local network though. Traceroute to an endpoint at the other site, where does it stop/die.

 

I've had multiple smoothwalls installs absorb 10.x ranges. I'm sure it's been down to dodgy customer config but we've had traffic enter but not return as it's been routed badly at the remote end.

Posted
You need routes to point the remote subnets towards your smoothwalls IPsec interface IP/VPN IP?

 

If the VPN is up, traffic just needs to be sent to that gateway, I would expect that to be part of the IPsec setup though...

This might be within your local network though. Traceroute to an endpoint at the other site, where does it stop/die.

 

I've had multiple smoothwalls installs absorb 10.x ranges. I'm sure it's been down to dodgy customer config but we've had traffic enter but not return as it's been routed badly at the remote end.

Traceroot on a device hits the smoothwall at the first hop and stops.

 

I think i've got the subnets setup correctly.

 

In terms of the "Gateway", is this the external IP of the smoothwall or the gateway IP of the network? What every i try it doesn't work.

Posted

Smoothwall as your gateway, or Smoothwall as the IPsec gateway?

I'll have to nose over how mines set up, not on a SW but it'll be the same.

 

My layer3 points that range towards my VPN gateway address from what I remember.

 

If you are getting to the VPN gateway, I'd say it the return end personally, or just one of the devices taking full ownership of the subnet and not sending return traffic back.

Posted
Smoothwall as your gateway, or Smoothwall as the IPsec gateway?

I'll have to nose over how mines set up, not on a SW but it'll be the same.

 

My layer3 points that range towards my VPN gateway address from what I remember.

 

If you are getting to the VPN gateway, I'd say it the return end personally, or just one of the devices taking full ownership of the subnet and not sending return traffic back.

In the Subnet page of Smoothwall it says Network, Subnet, Gateway. I'm presuming Gateway is the IP address of the remote Smoothwall device for that network.

 

Site A

Network: 172.16.24.0

Subnet: 255.255.248.0

Smoothwall: 172.16.24.8

 

Site B

Network: 172.25.160.254

Subnet: 255.255.248.0

Smoothwall: 172.25.160.254

 

Must admit, i wish Smoothwall gave some diagrams as examples in their documentation.

Posted (edited)
In the Subnet page of Smoothwall it says Network, Subnet, Gateway. I'm presuming Gateway is the IP address of the remote Smoothwall device for that network.

 

Site A

Network: 172.16.24.0

Subnet: 255.255.248.0

Smoothwall: 172.16.24.8

 

Site B

Network: 172.25.160.254

Subnet: 255.255.248.0

Smoothwall: 172.25.160.254

 

Must admit, i wish Smoothwall gave some diagrams as examples in their documentation.

 

Does your Smoothwall do your routing, or does a core switch?

 

Our default route out for the core switches is the SW IP.

 

Our setup for two sites is:

 

Site A (10.0.0.0/16) - Smoothwall IP 10.0.5.254, Smoothwall VLAN/Core Switch interface IP: 10.0.5.1

 

Subnet settings:

Network: 10.0.0.0

Subnet: 255.255.0.0

Gateway: 10.0.5.1

 

IP Sec settings:

Local IP:

Local Network: 10.0.0.0/16

Remote IP:

Remote Network: 10.10.0.0/16

 

Site B (10.10.0.0/16) - Smoothwall IP 10.10.5.254, Smoothwall VLAN/Core Switch interface IP: 10.10.5.1

 

Subnet settings:

Network: 10.10.0.0

Subnet: 255.255.0.0

Gateway: 10.10.5.1

 

IP Sec settings:

Local IP:

Local Network: 10.10.0.0/16

Remote IP:

Remote Network: 10.0.0.0/16

Edited by Jonah
  • Thanks 1
Posted (edited)
Does your Smoothwall do your routing, or does a core switch?

 

Our default route out for the core switches is the SW IP.

 

Our setup for two sites is:

 

Site A (10.0.0.0/16) - Smoothwall IP 10.0.5.254, Smoothwall VLAN/Core Switch interface IP: 10.0.5.1

 

Subnet settings:

Network: 10.0.0.0

Subnet: 255.255.0.0

Gateway: 10.0.5.1

 

IP Sec settings:

Local IP:

Local Network: 10.0.0.0/16

Remote IP:

Remote Network: 10.10.0.0/16

 

Site B (10.10.0.0/16) - Smoothwall IP 10.10.5.254, Smoothwall VLAN/Core Switch interface IP: 10.10.5.1

 

Subnet settings:

Network: 10.10.0.0

Subnet: 255.255.0.0

Gateway: 10.10.5.1

 

IP Sec settings:

Local IP:

Local Network: 10.10.0.0/16

Remote IP:

Remote Network: 10.0.0.0/16

 

By following this I've managed to lock myself out to the network via SSL VPN trying access the Smoothwall and the Network - long story but..

 

if anyone knows how add Smoothwall Access on ports 81 and 441 to an existing Smoothwall Access rule via SSH or CLi, please pipe up otherwise it means a full restore from backup.

 

Anyway i put the following into my (SiteA) Smoothwall Subnet page and it broke clients being able to communicate internally with the smoothwall at 172.16.24.8. The same happened at SiteB with the smoothwall at 172.22.192.2 (different site to the one earlier in the topic).

 

Site A (172.16.24.0/21) - Smoothwall IP 172.16.24.8, Smoothwall VLAN/Core Switch interface IP: 172.16 24.24

 

The Core switch has a line "ip route 0.0.0.0 0.0.0.0 172.16.24.8"

 

Smoothwall Subnet page settings:

Network: 172.16.24.0

Subnet: 255.255.248.0

Gateway: 172.16.24.8

 

IP Sec settings:

Local IP:

Local Network: 172.16.24.0/21

Remote IP:

Remote Network: 172.22.192.0/21

 

- - - - - - - - - - -

 

Site B (172.22.192.0/21) - Smoothwall IP 172.22.192.2, Smoothwall VLAN/Core Switch interface IP: 172.22.192.10

 

Site B has an Aruba 2930 with no IP ROUTE line listed.

 

Smoothwall Subnet page settings:

Network: 172.22.192.0

Subnet: 255.255.248.0

Gateway: 172.22.192.10

 

IP Sec settings:

Local IP:

Local Network: 172.22.192.0/21

Remote IP:

Remote Network: 172.16.24.0/21

Edited by timbo343
Posted
When on the cli type setup, then you have the “permit admin access” option that’ll create a new access rule on your selected interface. Hopefully that works out for you.
  • Thanks 1
Posted
When on the cli type setup, then you have the “permit admin access” option that’ll create a new access rule on your selected interface. Hopefully that works out for you.
Ah yes, thank you. I've got an old test smoothwall at home and have just run setup at the command prompt and it's brought up a menu

 

> Change Admin password

> Change Root password

> Hosrname

> Keyboard layout

> Network Interfaces

> Permit Admin Access

> Restore Configuaration

> Serial Console

 

Permit Admin access gives the option for

> All internal interfaces

> All external interfaces

 

Hope isnt lost just yet, just need to physically get to the box and plug in with a keyboard.

 

I've got ways i can get to the UI via the other VLANs on site 🤞🏻

Posted

If the Smoothwalls could talk to each other but not the subnets, the most likely cause is routing seen from the clients side. Is the Smoothwall the gateway for the remote subnets? If you had another solution for VPN before, there may be a static route in place?

 

The firewall policy should be LAN and IPSEC in both incoming and outgoing interface. As for Smoothwall access over SSL and VPN, make sure there is an access policy for the SSL VPN and IPSEC interface in Smoothwall access.

  • Thanks 1
Posted
Should be simple enough - all routes are added by the VPN engine so you don't need any additional ones adding. Firewall policies are the only ones that need to be added manually. Have you added and policies in the SNAT and LLB policies section? Make sure the policy for traffic to internal networks is at the top of that list.
Posted
Should be simple enough - all routes are added by the VPN engine so you don't need any additional ones adding. Firewall policies are the only ones that need to be added manually. Have you added and policies in the SNAT and LLB policies section? Make sure the policy for traffic to internal networks is at the top of that list.

 

Oh hang on. That rule:

 

Source IP: Any

Destination IP: Internal Networks

Service: Any

SNAT: X

LLB Pool / Gateway: Automatic

Enabled: Tick

 

Needs to be at the top of the list?? It was at the bottom on smoothwall 172.16.24.8 - that could be the issue??

Posted
Yes - if there are policies that affects that traffic before the internal networks policy then the traffic wouldn't be sent via the ipsec tunnel. That would explain you seeing traffic going to the Smoothwalls but no further. It gets shunted out via the external gateway and disappears forever...lost...alone... ;)
  • Thanks 1
Posted
If the Smoothwalls could talk to each other but not the subnets, the most likely cause is routing seen from the clients side. Is the Smoothwall the gateway for the remote subnets? If you had another solution for VPN before, there may be a static route in place?

 

The firewall policy should be LAN and IPSEC in both incoming and outgoing interface. As for Smoothwall access over SSL and VPN, make sure there is an access policy for the SSL VPN and IPSEC interface in Smoothwall access.

 

Thank you so much!!! Got it working.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...