Jump to content

Recommended Posts

Posted

Has anyone got Xentools onto Smoothwall NG? Or (if Tom's watching) do Smoothwall have a solution for this already (have had a browse through the support site, but nothing mentioned.

 

Cheers

Posted

I'm watching, yeah :) I believe it has been done - but as far as I know, you have to use SmoothWall outside of the paravirtualised mode.

 

Will get some more info on this and get back to you.

  • 5 weeks later...
Posted
Has anyone got Xentools onto Smoothwall NG?

 

I've just been told by SmoothWall technical support that SmoothWall doesn't work under Xen. The install procedure seems to run okay, but when SmoothWall reboots after install it doesn't bring any ethernet interfaces up. Running "ifconfig -a" shows me an ethC and ethD, and if I give ethC an IP address and bring it up ("ifconfig ethC 10.0.0.2", "ifconfig ethC up") I can ping 10.0.0.2 from my workstation and get a reply, however I can't log in to any web interface on 10.0.0.2 (I assume because nothing's listening).

 

Willott: did you configure a Xen VM to run SmoothWall? If so, how did you get the networking to work?

 

--

David Hicks

Posted

We're actually buggering about with various virtualisation platforms in the office today - got NG looking fine on Xen, albeit not the paravirtualised one. Compatibility with more hypervisors (and full support) is high on our list.

 

I'm not in the office tomorrow, but call and speak to Rob Faulkner - 0113 3874181 see what he can help you with.

  • Thanks 1
Posted
We're actually buggering about with various virtualisation platforms in the office today - got NG looking fine on Xen, albeit not the paravirtualised one. Compatibility with more hypervisors (and full support) is high on our list.

 

I'm not in the office tomorrow, but call and speak to Rob Faulkner - 0113 3874181 see what he can help you with.

 

Is there any eta with this / beta testing? Or anything we can do to help with testing? I'm also interested in SG on Xen, mainly so I can convert my last ESXi host over (it's holding the SG vm).

Posted

Pete,

 

No ETA on "make it perfect" - tho working paravirtualised on Xen should be in before the end of next year, but we already have NG on a couple of Xen servers. One seems to have worked a whole metric buttload easier than the other. I am a few steps removed from the process ATM though - I will call Rob and point him in this general direction ;-P

Posted

Running Xenserver 5.0 update 3 and have it running successfully (though possibly a little slowly due to the kind of virtualisation used). I believe that there's someone at Smoothwall running a cluster of NGs on Xen (the hardcore kind, not the Citrix version), so it definitely runs. I didn't have any issues with networking - created a new machine with a single interface in Xenserver, ran install - configuring NIC. Job done (as far as I remember). Sorry I can't be more help! Maybe try reinstalling with a single NIC, then add a second once you have the first working (it's strange that they show as ethC and ethD tbh).

 

@Tom: I'd be happy to test any Xen Kernel stuff if you need it - I believe for Xen support it's a kernel patch (I seem to remember Imran finding a link to something of use) - get on with it ;) :p

 

Possibly useful and interesting links:

XenParavirtOps - Xen Wiki

Also seems that on xen.org there are sources for kernels with Xen bits already in (would mean adding in necessary NG bits, but the Xen bit would be done!)

Posted
One seems to have worked a whole metric buttload easier than the other.

 

Slightly off topic (well... quite a lot) - but I'm not aware of a quantity of a metric buttload - how does it compare to an imperial buttload?

 

Back on topic - what difficulties were there (I guess this is where Rob could probably answer)?

Posted
Slightly off topic (well... quite a lot) - but I'm not aware of a quantity of a metric buttload - how does it compare to an imperial buttload?

 

Back on topic - what difficulties were there (I guess this is where Rob could probably answer)?

 

They are the same - but you can get fined off the EU for using metric. Apparently :)

 

Difficulties were between citrix xen and "hardcore xen" I think.

Posted
Running Citrix XenServer 5.5 here with Smoothwall installed for several months. Not using it in production yet (still testing!), but it's been working fine for us in the non-paravirtualised mode :)
  • Thanks 1
Posted
(it's strange that they show as ethC and ethD tbh).

 

I'm running the open source version of Xen that comes with CentOs 5.1, which is probably getting on a bit now. Hmm, I suppose I could try upgrading the version of CentOS used on the server?

 

The VM's config file configures networking in the following way:

 

vif = ['type=ioemu, bridge=xenbr0', 'type=ioemu, bridge=xenbr1']

 

Which seems standard enough - certainly when the VM starts up, a vifx.0 and vifx.1 get placed in xenbr0 and xenbr1 bridges respecitvly. Oddly, I've just noticed that the two ethernet ports that SmoothWall recognises seem to get enumerated differently every time the VM reboots - we're now up to ethI and ethJ. This means that, on reboot, SmoothWall looks for, say, ethF but doesn't find it because it's now called ethI. Anybody any idea why it does this, or seen anything similar happen?

 

--

David Hicks

Posted

I used to have an issue on my old home file server whereby it would swap the network ports around on reboot (so my external IP would suddenly be on the internal card and vice versa). I can't remember fully, but I may have used udev to resolve - the dell article below seems to give some clues (page 3 has details about the udev line) - whether Smoothwall has udev or not I'm not sure (and I'm not sure how it may affect the machine). Can you specify mac address in the Xen machine config? Just a random wondering as to whether the mac address of the virtual nic is changing and causing issues.

 

http://www.dell.com/downloads/global/power/ps1q07-20060392-Domsch.pdf

Posted
It appears within your Smoothie, the area to dig through is /settings/ethernet/settings and /settings/ethernet/nics/settings-*. The nics/settings-* files seem to have MAC address assigned in there, so that may be somewhere to look.
  • Thanks 1
Posted
the area to dig through is /settings/ethernet/settings and /settings/ethernet/nics/settings-*.

 

Thanks. I've been doing lots of Google searching today, trying to figure out what's going on. I found this:

 

http://www.edugeek.net/forums/internet-related-filtering-firewall/30426-smoothwall-school-guardian-eval.html

 

Which came in handy. I've got to the stage where I can re-run setup and get the SmoothWall VM to connect to the network and act as a gateway, I've just got to get it to keep its settings when it reboots. I don't want to have to reconfigure its network from the console every time we switch the machine off.

 

--

David Hicks

Posted

Been distracted since I first saw this thread this morning, so apologies for the delay. I've always had great difficultly determining what people are talking about with the difference between (using aforementioned terminology) "hardcore" Xen and citrix Xen. I've only used the Citrix one which was effortless to install SW software.

 

Now I haven't had the pleasure of getting my hands dirty with the hardcore stuff, but I gather from one of my colleagues that

 

The VM's config file configures networking in the following way:

 

vif = ['type=ioemu, bridge=xenbr0', 'type=ioemu, bridge=xenbr1']

 

 

causes problems as Xen likes to give it a new MAC address every time it reboots. Smoothie currently evaluates this as a new network card and hence causes all sorts of problems.

 

I am lead to believe that doing something like

 

vif = [ 'type=ioemu, bridge=eth0, mac=00:16:3E:23:8D:36' ]

 

to hard-code a MAC address in there will stop this. That's the way VMware and the like configure their VMs.

 

As I said though, i've yet to try this myself - I'll have a chat with the main guy here who deals with the hardcore xen stuff when he returns from a brief hol on Monday if there's anything else.

 

And to reiterate, Citrix Xenserver seems trouble free. If only the naming wasn't as confusing.

  • Thanks 1
Posted
Xen likes to give it a new MAC address every time it reboots

 

Indeed. Typed the previous message, thought "hang on a minute...", changed the VM's configuration, all works fine now. Then checked back here and found the answer waiting for me :-)

 

Incedently, I also had a bit of a problem getting SmoothWall to see the harddisks provided by Xen. In the end, this worked:

 

disk = ['file:/mnt/ACSGATEWAY003OS/ACSGATEWAY003OS.img,ioemu:hda,w']

 

I.e. a file sat on an ext2 filesystem contained in an LVM volume, which is probably a few more layers of adstraction than is stricly healthy.

 

--

David Hicks

Posted

I've been looking at SmoothWall (primarily Guardian filtering) on Amazon Cloud. I got it working but it's a lot of effort. Once working it's great and can provide a nice cluster (resizeable easily) of load balanced Guardians authing against, for example, an Active Directory. But initial set up is very hard. Making it not hard is high on our priority list. The reason it's hard includes issues like AC does not have a console so it's not possible to interactively solve networking issues if you can't ssh to it. They also don't allow you to run your own Kernel.

 

Imran has Network Guardian working on a standard Debian with standard apt-get-able xen. The NG requires no modifications and works happily and can have updates including new kernels and reboot and is great. This is in un-modified guest mode. He had to do things like robf listed like give it a static mac address and some networking stuff I don't understand. But these were just config options and the NG is unmodified and fully standard production.

  • Thanks 1
Posted

Hi Daniel,

 

I've spoken to Imran before, and he was also looking to get the kernel modified to allow for full xen support and better speed (it does seem to run fairly slowly in Xen currently), so when there's a beta, we'd be more than happy to test it for you!

 

Amazon cloud sounds very interesting - would you be looking to load balance through RRDNS or some form of IP load balancing? Sounds like it may be a very good base for an ISP filtering solution!

 

Cheers

 

Will

Posted

I've spoken to Imran before, and he was also looking to get the kernel modified to allow for full xen support and better speed (it does seem to run fairly slowly in Xen currently), so when there's a beta, we'd be more than happy to test it for you!

 

It does not feel like it's slow although I've done no specific tests. Yes Imran was going to do that at some point. However I beat him to it with AC which is one way. Another is to add the xen patches to the kernel. When there is anything to test I will let you know but it will be some time away.

 

 

Amazon cloud sounds very interesting - would you be looking to load balance through RRDNS or some form of IP load balancing? Sounds like it may be a very good base for an ISP filtering solution!

 

AC provides a load balancer. Info here: Elastic Load Balancing

 

Works great.

Posted
Once working it's great and can provide a nice cluster (resizeable easily) of load balanced Guardians authing against, for example, an Active Directory.

 

Could a school (or LA) use this to provide a filtered connection from home - give pupils laptops usable at home and school that always went through an Amazon Cloud-based filter?

 

Does the Active Directory server also have to be cloud based, or does that run on servers inside the school somewhere?

 

--

David Hicks

Posted
Could a school (or LA) use this to provide a filtered connection from home - give pupils laptops usable at home and school that always went through an Amazon Cloud-based filter?

 

Theoretically, yes. We do hope to do something like this in time. We may be up for a spot of further experimentation to see where we need to improve. If this is something that you'd be really interested in, PM me or daniel, can't promise anything but we will certainly take a look at the idea with you.

 

Does the Active Directory server also have to be cloud based, or does that run on servers inside the school somewhere?

 

Pass. That's one of the questions we'd need to answer. Certainly some method of securing the link between AD and filter is required - though amazon I believe offer a VPN. Wether the present (or next-gen (SOON!)) auth daemon would perform well over latent links isnt something we have tried - so it may need an alternate method, or maybe some fiddling with the auth cache. Again, this is on our "to play with" list, and we would welcome your input.

Posted
Could a school (or LA) use this to provide a filtered connection from home - give pupils laptops usable at home and school that always went through an Amazon Cloud-based filter?

 

Yes. You could do the same with a cluster of hosted NG on VMs or real boxes too. I have a test set up if you want to try it PM me.

 

Does the Active Directory server also have to be cloud based, or does that run on servers inside the school somewhere?

 

Amazon provide VPN from the cloud to your LAN. Although I've not yet tried it. The AD could be on your LAN or in the cloud. The one I set up was in the cloud. Actually you could have one on the LAN and a VPN to one in the cloud in the same domain.

 

Once filtering is hosted/cloud you will need some way of authenticating the user so it knows that you, first of all, have permission to use the proxy and which policy to apply and who you are for reporting and logging purposes. On a LAN you can use NTLM and thus have single sign-on and nothing to do when you start web browsing. To solve this for hosted you have to use auth methods that can go through the internet and it may require client software to do this depending on what you want to do. Plus a roaming laptop may be more tricky to lock down compared to a static PC on a LAN. So there's a number of interesting and different challenges.

  • 2 weeks later...
Posted

Hi all,

I'm new to xen and trying to run smoothwall express as a guest host on a Debian install with xen. At some point I might also install windows home server as a guest but right now my interest goes to the smoothwall install.

From what I understand I can install guest os's paravirtualized or the HVM way. I'm guessing smoothwall will have to go HVM but wanted to check out this thread since you seem to do this already.

Do any of you have a config file for smoothwall and am I going the right direction ?

And yes, I am well aware that people advice to run smoothwall on its own hardware. I still like to try this.

 

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...