Jump to content

getyourfill

Members
  • Posts

    17
  • Joined

  • Last visited

Everything posted by getyourfill

  1. Well I got it working finally. It was the IDS reference the ethernet port. Removing that rule allowed me to make the necessary changes.
  2. Yes after I recreate it the IP and hostname will be the same. I wish I had a second one of these things so I could figure this stuff out without messing with my production unit.
  3. I'll try it again either this evening or this weekend. Also -- how would this affect the certificate I created on the smoothwall? Would it remove the IP and then re-add it once the interface is created or would I have to recreate the whole certificate?
  4. I tried doing this and I must have missed a section. Does this also apply to the Web Proxy > Manage Policies page that has policies for transparent/non-transparent. I did your steps and when I tried to add the VLAN interface I got the error shown in the attached photo. I thought I got everything but when I looked in the web proxy authentication manage policies I saw a bunch of "DELETED" lines. Think this is the cause or would I have missed something else?
  5. I can't seem to find the documentation about how the smoothwall was originally set up, but I have only one internal interface / port set up on smoothwall and I would like to make some changes to it. In order to make the changes I want, I have to delete the IP address attached to the port. I am pretty sure I can't do all that from the one internal interface since deleting the IP would mean I'm no longer able to connect to that IP.How can I set up a second port on the smoothwall with a secondary IP that I can connect to so I can delete the original interface's stuff and rebuild? So like smoothwall internal right now would be 192.168.1.1/24. I want to be able to delete 192.168.1.1/24 and recreate it as an untagged vlan 192.168.1.1/24.
  6. I want to set up a second physical interface on my Smoothwall serving DHCP on VLAN40. Are there any steps I'm missing or have incorrect here? Set switch port connected to second physical Smoothwall interface as access port vlan 40. Create DHCP Server with 192.168.40.0/24 gateway 192.168.40.1 Go to interfaces Choose second interface and add vlan with a gateway ip of 192.168.40.1 Set the created vlan interface as tagged vlan 40. Then on switch -- Set ports 3,4,5 to untagged VLAN 40.
  7. I'm just wondering if Google auth is still supposed to work if you access it from the Non-SSL Login page? Google auth would still be secured since it goes through Google's side, right? It's just the local logins that would be insecure?
  8. If I use the URL pattern route how would this work in the case of a HTTPS site when requiring SSL Login? I don't want the full domain allowed for users, but I need the URL with "MDN-Phrase" to be allowed all the time no matter if the user is authenticated or not. Is it possible to do that without also completely allowing the base domain?
  9. I am trying to allow a few specific URLs: https://cdnjs.cloudflare.com/ajax/libs/socket.io 2.2.0/socket.io.js any URL that has "MDN-phrase" in it. How should I enter the regex exactly to allow these?
  10. My first time having to do this.. I'm reading over the KB and it says push the newly created CA out before changing the default cert in Smoothwall. Will this not cause any problems for users since they'll have two different certs for the same domain installed? Also, this page says browsers will only accept Year long certs: https://techbeacon.com/security/google-apple-mozilla-enforce-1-year-max-security-certifications Is this not going to affect the Smoothwall cert that's set for 3 years?
  11. I've got multiple VLANs kind of working on my Smoothwall and they do receive a transparent filtering policy, but I'm not sure about the filter/SSL/Google login page for more granular access. What determines if the Smoothwall's SSL/Google clogin page can be accessed? Can I allow users on multiple VLANs to authorize to the filter without giving the ability to access the administration login portal? Would I expect each VLAN to access it on their own subnet or would I include a route to just one so that no matter what VLAN they all hit 1.2.3.4:XX/clogin ?
  12. I can't find a good tutorial on this anywhere for Smoothwall. I would like to set up a guest VLAN that is completely unfiltered, but I'm really struggling to see how to do this on Smoothwall. My current setup: L2 managed switch -> smoothwall NIC2 [dhcp/firewall/router] -> internet NIC2 has basic interface with 1 IP address added I can't add a VLAN with parent interface NIC2. I can only add VLAN to other NICs. Why is that?? I can see how to create two DHCP servers, but I can't see how you specify which VLAN/interface the DHCP server is on. Is it just a matter of creating each DHCP server to match the network of each VLAN interface you create with the default gateway matching the IP added to the VLAN interface? Would I set up a trunk port from my switch with both VLANs to the NIC2 on the smoothwall? How can I get this set up without accidentally locking myself out of my smoothwall? Ideally I'd like to just have all the currently untagged traffic stay working as it is and then add this second VLAN that could be unfiltered.
  13. So I should be getting the safeguard alerts even if I'm not paying for the extra 'cloud reporting' ? If so, I'll have to test it again
  14. I set up the hybrid cloud filtering with a small subset of users and I'm not sure it was worth it. It did smooth out the authentication process a lot, but the lack of reporting on-site really set me back. I don't think I'm getting any kind of filtering alerts now if they're doing something they aren't supposed to. I tried making some searches on a test account that would normally be flagged and give me an instant-email, but I got no such alert on the hybrid user. I didn't expect to lose all the alerting and reporting.
  15. Smoothwall already has Google directory for authorizing accounts to the filter.. Does it have a mechanism for also providing RADIUS?
×
×
  • Create New...