MatthewShaw Posted September 4, 2025 Posted September 4, 2025 Hi, Hoping someone can help as this is driving us mad. We have migrated our network over the summer from a traditional onprem set up to AD linked to M365/Intune/Entra. Deices are not AD linked. We run a Smoothwall VM for Firewall and filtering. We have an issue where a majority of students logins take around 10 minuets and some of them when they do log in have a blank screen. Some students seem to login without issues.The company that has delivered the migration are blaming Smoothwall and Smoothwall are blaming them. Leaving us stuck in the middle with our student devices effectively useless. Has anyone experienced similar issue or can anyone give any pointers on what to look at? as always any advice is really appreciated. Many thanks
kierans Posted September 4, 2025 Posted September 4, 2025 (edited) Have you tried a device on a hotspot? If the issue persists likely not smoothwall and vice versa Edited September 4, 2025 by kierans
psynegy Posted September 4, 2025 Posted September 4, 2025 You're running on-prem Smoothwall filtering instead of using the Smoothwall Cloud browser extension? If you're using the extension, then the devices shouldn't really be filtered by your Smoothwall box (double filtering). Assuming that you're just using the extension, there wouldn't be much to blame on Smoothwall if there's no filtering happening outside of the browser... As kierans said, taking a device out of the Smoothwall network will be an easy way to check for it's involvement (assuming no DirectAccess or similar VPN involvement!)
MatthewShaw Posted September 5, 2025 Author Posted September 5, 2025 Thanks. Everything works offsite. We're currently in discussions with our ISP as testfiltering.com throws errors when we plug directly into the router, the ISP claims there is no firewall configured (exponential-e), the issues look to be TLS related.
PaddyNewman Posted September 7, 2025 Posted September 7, 2025 What TLS errors do you get? I thought most expo-e lines were just DIA and you ran your own firewall, that was the instance at some schools we used to support, the primaries went to a hosted fw but the secondaries had their own on prem firewall. I wonder, do you get the same TLS errors on non managed devices, mobile phone/BYOD for ex?
MatthewShaw Posted September 7, 2025 Author Posted September 7, 2025 Hi. After working with the ISP on Friday we found some errors on the line. We didn't delve very deeply into the the TLS errors as we're only using them as an indicator to give Smoothwall and the ISP a pointer. As it stands we still haven't rules out Smoothwall nor the ISP and have further testign scheduled for Monday which will give us a bit more clarity as it could still an issue with the inTune build process being filtered by Smoothwall (I thought this was rulled out until a passing comment from our contractor). I'll come back to the thread after that To answer your question though, the odd thing is, we get TLS errors on everything behind Smoothwall and everything when we connect directly to the ISP. However if I connect to the old Smoothwall everything works, if I connect directly to the ISP via the same public IP as the old smoothwall we get TSL errors??? - the assumption here is that the old Smoothwall is doing some traffic shaping to fix an issue with the ISP.
PaddyNewman Posted September 7, 2025 Posted September 7, 2025 WAN interface MTU difference? I've seen weird stuff recently with MTU. Perhaps jumping the gun a bit but check to see if the old one is configured slightly differently.
psynegy Posted September 7, 2025 Posted September 7, 2025 12 hours ago, PaddyNewman said: WAN interface MTU difference? I've seen weird stuff recently with MTU. Perhaps jumping the gun a bit but check to see if the old one is configured slightly differently. This. We’ve had a similar issue with an ISP before having a badly configured MTU somewhere along the lines. Run lots of MTU tests, bet that’s where your issue is! Hopefully yours is resolved faster than ours. Ours was many, many months before they believed us enough to actually look into it. Oh boy did we ever get a big apology…
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now