Jump to content

Recommended Posts

Posted

I'm trying to migrate our old system to use the Smoothwall as the whole UTM - the way the system I inherited was setup was that the Smoothwall is set as the proxy, and then the Smoothwalls internal interface points to our Cisco firewall as its gateway

 

This works - traffic proxied to the Smoothwall goes to the firewall and then out to the internet

 

Now, as I'm planning to remove the old firewall I added an external interface to the smoothwall, gave it an external address (from our ISP range) and set the gateway of the external address to be the ISP provided gateway

 

All good, so I thought all I need to do now is to switch the gateway of the internal address to None as it will use the new External interface, but when I try that it fails with two errors:

  • Gateway: IP is not in use as a gateway
  • Local address: Addresses without a gateway cannot be used in an LLB pool

 

I must be missing something here, as instead of directing the outbound traffic to the firewall it should be able to use the external interface (which is tested and working) to bypass the firewall? This is stage 1 of migrating stuff away from the firewall so I'm using spare external IPs that the ISP allocated

Posted
2 minutes ago, Joeloman said:

Are you sure you have set the role of the new interface to External?

Definitely - its the only External interface as the previous setup was using the firewall as the gateway.

Posted

I don't have much more to say other than to check that there is a Firewall rule that allows traffic from the internal network to the external one.
Just like Tom says, contact support.

Posted

OK, Thanks - I've logged a ticket. The way it was originally set up seems overcomplicated to me which is why I want the Smoothwall to be the new firewall  - and publish an RDS server through it as well

Posted
6 minutes ago, tom_newton said:

My advice would be don't port forward to RDS if you can help it - prefer VPN

We have a vpn on our old cisco box so trying to move away from this, RDS is something I've used before as its cross platform but I've not looked at the smoothwall vpn as an option to be honest. Might have to research that a bit as well

  • Like 1
Posted

Definitely feel safer with rds behind a vpn. The smoothwall supports openvpn, or, another option is to have users use Windows vpn to connect to azure vpn gateway, and connect that to the smoothwall via ipsec (we use both methods internally) 

Posted

I was planning rds with mfa but will look into smooth wall vpn - couldn't find much in the way of documentation for this though. Still need to get the new external connection working either way!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...