Jump to content

Recommended Posts

Posted

Hi,

 

I'm trying to get my head round how this network I've inherited works. 

 

Aruba switches with Smoothwall.

 

The Smoothwall has 2 internal interfaces.

 

1   10.13.88.01

2. 10.100.100.2

 

I can see 2x transparent proxies setup

 

10.100.100.2:80 with Core Auth setup and Allow transparent HTTPS incompatible sites

10.13.88.01:80 with Core Auth and Block no SNO header traffic.

 

I'm trying to work out how traffic is routed to each one.

 

VLAN 10 is the main LAN - DHCP dishes out the IPs on the range with the Router set to 10.13.91.231 which is the core switch IP address for the VLAN

VLAN 20 is the other VLAN  - DHCP out the  out the IPs on the range with the Router set to 10.20.0.1 which is the core switch IP address for the VLAN

 

There's one IP route on the switch - ip route 0.0.0.0 0.0.0.0 10.100.100.2

 

I'm trying to work out how traffic is going to one smoothwall port and not the other. I was told that guest traffic didn't need cert for blocking... but I am sceptical.

 

I can see some tags on the core ports connecting to the smoothwall but its messy.

 

The Smoothwall port for 10.13.88.01 is plugged into another switch with VLAN 10 untagged which I presume is how its getting the traffic??

 

Writing this down sort of makes it make more sense.. :)

Posted

"There's one IP route on the switch - ip route 0.0.0.0 0.0.0.0 10.100.100.2"

 

That's your static route, so I'm guessing routing is enabled on the core switch (as it's acting as the gateway on your internal ranges) then that static route acts as the gateway address for the core to route internet traffic.

 

What is the subnet mask on VLAN10?

 

Either it's massive and also includes 10.13.xx.xx, or it could be related to some legacy setup (physical guest segregation or something) that doesn't exist anymore.

 

Also going to assume there's an external interface that does to off to ISP equipment if it's a simple setup.

Posted

I've just reread your middle bit.

 

Looks like VLAN 10 is a huge subnet.

 

The static route on the core is what's telling all external traffic to go via 10.100.100.2.

Posted

Thanks for the replies, really helpful. 

 

So more testing.

 

Devices on the old LAN in the 10.13 range get sent to the 10.13.88.26 SW Lan.

All other devices 10.200 / 10.30 /10.20 all go out on the 10.100.100.2 SW Lan.

 

VLan 10 is a 255.255.252.0 subnet.

 

The SW port 10.100.100.2 address assigned to it is plugged into the core switch with VLAN 50 tagged, VLAN 20 tagged.

The SW port 10.13.88.26 is plugged into another switch with VLAN 10 untagged and VLAN 30,40,50,60,168 all tagged.

 

So because the switch port is untagged on VLAN 10 connected to switch all traffic goes out through that on that VLAN?

 

Actually... port B1 which has the SW port  10.100.100.2 plugged into it is called routing and is untagged (was on page 2 of the gui so I missed it)

Posted

So the switch as the core is where all your internal traffic is hitting, the static route is telling everything to use the smoothwall IP as the next hop to get out to the internet.

I'm guessing your core switch config in the CLI will have a line that just says "routing" or "IP routing". So that's the routing device for anything internal, then the smoothwall is the routing device for that (using the 0.0.0.0 static route).

Posted

Im just guessing but if you are wondering why it’s been designed like this The 10.13 network smells like an ip range used in the embc network range back in the olden days! and the new ranges were used to expand the amount of IPs available.

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...