caffrey Posted July 14, 2010 Posted July 14, 2010 were currently setting up our network with wireless access points with multissid to enable guest internet access, so far so good - we have the aps working accross the switches etc. Now we need to configure schoolguardian so that secured traffic (domain) goes through NTLM authentication and the unsecured vlan traffic goes through transparent - how do we go about this ? would we need more than 2 nics ? cheers
tom_newton Posted July 14, 2010 Posted July 14, 2010 That's a tough one. SchoolGuardian hasn't got VLAN support due to the way it was built. The next ISO of it is likely to have this. If you need VLAN support, ask your salesperson to swap it out for our commercial firewall product which does. I'd suggest using a second, unauthenticated filter port. This will mean you have to let "unauthenticated IPs" access all the sites that you want the unsecured lan to access, but this should not be a big issue. If you want to do transparent filtering though, it could give people on the secure LAN a way to access the sites those on the insecure LAN can access, but without logging a username, which may cause you issues?
caffrey Posted July 14, 2010 Author Posted July 14, 2010 Hrrm, that's torn it, i was under the impression that it would especially in relation to this post http://www.edugeek.net/forums/internet-related-filtering-firewall/58458-smoothwall-updates.html#post531182 as its a similar issue, back to the drawing board then ? or any more suggestions ? Thinking out loud maybe redirect somehow to second port authentication settings ?
tom_newton Posted July 15, 2010 Posted July 15, 2010 It will, you'll just need to shift the platform, which is a bit of a pain in the backside
DMcCoy Posted July 15, 2010 Posted July 15, 2010 It may not support the authentication combination you want (yet), but it does support using tagged vlans, however I already have 2 NICs so don't know if it would work with only one. I am using a couple of vlans, as I need 4 interfaces.
caffrey Posted July 15, 2010 Author Posted July 15, 2010 basically my idea was :- add vlan to the "internal" nic then add transparent to the proxy then enable the proxy on the vlan and the "internal" nic then add dhcp for the vlan so basically anyone using the guest access on the aps would go throo the firewall, wouldn't need authenticating and the proxy would act transparent (filtering isnt a huge issue on guests - as long as we can monitor and restrict bandwidth and ports (torrents etc)) plan b will maybe involve an express box / m0nowall - push comes to shove - just wanted less devices in the cab / configure
tom_newton Posted July 15, 2010 Posted July 15, 2010 Feel free to use your SG licence for the second box as well, as long as your guardian licence covers all the endpoints in the school, we don't particularly mind how you do it 1
jpaterson Posted January 8, 2011 Posted January 8, 2011 Does this extension of SG license to another box cover Advanced Firewall as well? By endpoints, does that refer to the number of concurrent SG licenses in the box?
john Posted January 8, 2011 Posted January 8, 2011 By endpoints Tom will mean if you licence for 300 PCs, then between your two (or more) installs you do not exceed 300 PCs in total.
jpaterson Posted January 11, 2011 Posted January 11, 2011 Does this extension of SG license to another box cover Advanced Firewall as well? Is Advanced Firewall covered as well?
jpaterson Posted January 11, 2011 Posted January 11, 2011 Sorry, my interpretation of this seems too good to be true. So, just to check...would we have to get another license to install advanced firewall, and our existing or additional SG endpoint licenses could be on the new box. Sorry if I'm being a dumba$$ asking this, but I don't wanna be breaking any laws.
tom_newton Posted January 11, 2011 Posted January 11, 2011 Sorry, my interpretation of this seems too good to be true. So, just to check...would we have to get another license to install advanced firewall, and our existing or additional SG endpoint licenses could be on the new box. Sorry if I'm being a dumba$$ asking this, but I don't wanna be breaking any laws. Give me a call after BETT and we'll sort it out (or come to the stand if you're at BETT), but if i'm thinking right you aren't going to have to dig too deep to do what you want
jpaterson Posted January 11, 2011 Posted January 11, 2011 (edited) You're a gem, Tom. I hope that they are paying you enough over at SmoothWall ;-) Hope BETT goes well and not too stressful for y'all. I think I've got your details in my inbox, so I'll give you a call early afternoon Monday. Edited January 11, 2011 by jpaterson typo
jpaterson Posted January 18, 2011 Posted January 18, 2011 Thanks for speaking with me over the phone. Looking forward to the forthcoming update!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now