Jump to content

Recommended Posts

Posted

Hello All,

 

I am new to SmoothWall and we have a VM appliance with this installed currently.  We have added the subnets to the SmoothWall appliance.  We have added 2 Network ports along with the Management port.

 

The SmoothWall sits between the external firewall and the LAN.

 

We have a couple of Guest networks.  These are DHCP'd etc.

 

We have added 2x network ports to the SmoothWall VMware appliance so the Guest networks can use these.  However, no matter what we try, we are having trouble setting this up and don't even know whether this is the right way to do this.

 

In my head and on paper I have:

 

  • NIC 1 to use the Guest 1 network - set in the VMware appliance with the VLAN.
  • NIC 2 to use the Guest 2 network  - set in the VMware appliance with the VLAN.

 

SmoothWall have not been very helpful on this.  Does anyone have a similar type of setup or any pointers for how this is to be setup?

 

The traffic from the Guest network needs to go to the SmoothWall before this hits the firewall.

 

Many Thanks.

Posted

I used the following process when setting up VLANs for different wireless networks.

1. Added new interfaces for the VLANs

2. Added DHCP servers with relevant scope (Smoothwall said it wasn't recommended to use them for DHCP, but it would not have been easy to use another system)

3. Created Locations to cover the DHCP scopes

4. Setup new web authentication proxies to treat the new interfaces appropriately e.g. staff, students

(VLANs had to be added on the switches of course, ports taggged)

 

I've also found Smoothwall support to be a bit unhelpful when it came to network config, but did get there in the end.

Posted

Find the easiest thing to do in these sorts of scenarios is to break it down into smaller chunks

 

  1. Plug a laptop into a switch port configured as an access port for the vlan, see if you get an IP
  2. If you cannot get an DHCP IP then give the laptop a static address in correct range and ping the gateway (not sure if you need to allow ping on the interface for this)
  3. See if you can trace the MAC address of the laptop to the Smoothwall if possible or at least the physical switch port that connects to the HyperVisor, (what HyperVisor is it BTW).

Do the APs need the extra vlan adding to the switch port where the APs plug into, some APs do including Unifi.

  • Like 1
Posted (edited)

@Gongalong Thanks for the reply.  The DHCP is interesting and something I will check.  I presume the DHCP needs adding to the SmoothWall?  A couple of questions.

 

1. We already have the Guest VLANs in place and working for some years.  Are you suggesting new VLANs for the Guest WIFIs?

 

2. From your reply, I think we have done as you have suggested in that we have created 2x network interfaces on the SmoothWall VM with the appropriate VLAN on the network interface.  My only doubt is what gateway should we use for the next hop.  The GW as it stands currently is already in the SonicWall device.  Do we need to add the GW so it is in the Guest network interface in the SmoothWall or add a new GW?

 

@Davit2005 Thanks for the reply.  The VLANs are WIFI only.  We csn use a WiFi device and obtain an IP in the correct VLAN.  I can see the MAC on the SonicWall albeit packet dropped.  I will check the SmoothWall device too.  The HyperVisor is VMware ESXi.  I believe I am missing a hop or GW somewhere.  Not sure where though.

 

You are both right in that the SmoothWall support is terrible!

 

Many thanks both.

 

Edited by sparktech
  • Like 1
Posted

Yes to setting up on the Smoothwall, under Services. Perhaps it causes a system load issue, not that the appliance has reported a problem *shrug*

 

I put each SSID on a separate VLAN, as we definitely don't want traffic on our VISITOR wi-fi talking to the staff LAN. And ditto for the other wireless networks (we upped it to four).

 

For the gateway question, each VLAN is going to need its own gateway. Best to check with Smoothwall support.

 

My experience with Smoothwall support isn't terrible, but the last few years the response time has got longer and longer, to the point now where it's 1-2 weeks. I also felt the network support was a bit lacking, but I was dependent on their advice as it's their system. We did get there in the end.

Posted

@Gongalong We are setup the same way, no VLAN crossover so thats good.  The GW for the Guests VLANs is currently on the SonicWall device.  So the process currently is:

 

IP received from the Guest DHCP scope.  The GW for the Guest scope is on the SonicWall for access.  This currently works as expected.

 

Now the SmoothWall is in the mix, does the GW for the Guests network interface  need to be on the SmoothWall and the SonicWall - the same GW on both devices?

 

Thanks.

Posted

So I am assuming you want to use these two “guest” networks for web filtering? or just passing traffic to your sonicwall as its inline?

If its transparent filtering, your dhcp will need to set the gateway as the smoothwall IP, the smoothwall Internal interface wont need a gateway as it will use your external interface to then go out. 

Have you configured the new interfaces under web proxies?

Feel free to PM. We’ve had Smoothwall for years on end, currently support over 14 sw boxes so like to think i can help out. 

Posted

@CrootUK Hello and thanks replying.  Yes, we will be using for web filtering before traffic hits the SonicWall.  I assume that's what you mean by transparent filtering?  I'll PM you if that's OK. 

 

In a nutshell we currently have Guest Vlan network > soon to be retired web filtering (cloud) > SonicWall.

 

New setup will be Guest Vlan > SmoothWall > SonicWall.

 

Many thanks

  • 5 weeks later...
Posted

Hello All,

 

After a fairly lengthy conversation with various people, it seems all we need is an IN and OUT setup.  I have done the following.

 

  • Virtual Machine created with 3x NICS.  1x MGMT, 1x NIC IN and 1x NIC OUT
  • Management NIC in place with IP for access.
  • Bridge NIC in SmoothWall.
  • NIC's IN and OUT attached to the Bridge NIC in SmoothWall.
  • Apparently no IP needs to be set on the Bridge or the NIC IN and NIC OUT attached to Bridge NIC.

 

My questions are:

 

  • Do I need to add the Guest WIFI SSID's to the NIC IN on the SmoothWall virtual machine or the NIC OUT?
  • Do I need to create additional VLAN's for the Guest WIFI SSID's and add these to the SmoothWall NIC in any way shape or form?

 

Happy to answer any other questions as needed.

 

Many thanks,

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...