Sheridan Posted October 27, 2025 Posted October 27, 2025 I'm trying to migrate our old system to use the Smoothwall as the whole UTM - the way the system I inherited was setup was that the Smoothwall is set as the proxy, and then the Smoothwalls internal interface points to our Cisco firewall as its gateway This works - traffic proxied to the Smoothwall goes to the firewall and then out to the internet Now, as I'm planning to remove the old firewall I added an external interface to the smoothwall, gave it an external address (from our ISP range) and set the gateway of the external address to be the ISP provided gateway All good, so I thought all I need to do now is to switch the gateway of the internal address to None as it will use the new External interface, but when I try that it fails with two errors: Gateway: IP is not in use as a gateway Local address: Addresses without a gateway cannot be used in an LLB pool I must be missing something here, as instead of directing the outbound traffic to the firewall it should be able to use the external interface (which is tested and working) to bypass the firewall? This is stage 1 of migrating stuff away from the firewall so I'm using spare external IPs that the ISP allocated
Joeloman Posted October 27, 2025 Posted October 27, 2025 Are you sure you have set the role of the new interface to External?
Sheridan Posted October 27, 2025 Author Posted October 27, 2025 2 minutes ago, Joeloman said: Are you sure you have set the role of the new interface to External? Definitely - its the only External interface as the previous setup was using the firewall as the gateway.
tom_newton Posted October 27, 2025 Posted October 27, 2025 Beyond me I am afraid - open a ticket and let me know and I will make sure it hits second line
Joeloman Posted October 27, 2025 Posted October 27, 2025 I don't have much more to say other than to check that there is a Firewall rule that allows traffic from the internal network to the external one. Just like Tom says, contact support.
Sheridan Posted October 27, 2025 Author Posted October 27, 2025 OK, Thanks - I've logged a ticket. The way it was originally set up seems overcomplicated to me which is why I want the Smoothwall to be the new firewall - and publish an RDS server through it as well
tom_newton Posted October 27, 2025 Posted October 27, 2025 My advice would be don't port forward to RDS if you can help it - prefer VPN
Sheridan Posted October 27, 2025 Author Posted October 27, 2025 6 minutes ago, tom_newton said: My advice would be don't port forward to RDS if you can help it - prefer VPN We have a vpn on our old cisco box so trying to move away from this, RDS is something I've used before as its cross platform but I've not looked at the smoothwall vpn as an option to be honest. Might have to research that a bit as well 1
tom_newton Posted October 27, 2025 Posted October 27, 2025 Definitely feel safer with rds behind a vpn. The smoothwall supports openvpn, or, another option is to have users use Windows vpn to connect to azure vpn gateway, and connect that to the smoothwall via ipsec (we use both methods internally)
Sheridan Posted October 27, 2025 Author Posted October 27, 2025 I was planning rds with mfa but will look into smooth wall vpn - couldn't find much in the way of documentation for this though. Still need to get the new external connection working either way!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now