Koozali.org: home of the SME Server

Disabling firewall/masquerading in server/gateway mode ?

detspmehd

Disabling firewall/masquerading in server/gateway mode ?
« on: June 09, 2006, 06:39:07 AM »
I support a small parochial school (as a parent technology volunteer) which currently has two SME servers operating in gateway/server mode.   One server has all the teacher staff accounts on a VLAN and the other server has all the student accounts on another VLAN.
These two VLAN’s connect to a third default VLAN to get to the public internet.  On the default VLAN I am running Smoothwall Express 2.0 as our linux internet firewall and internet content filtering software.  

This is my problem which I haven’t found a solution yet:

The SME server operating in server/gateway mode is running a firewall which is preventing my internet firewall from receiving “ident” user information and “actual” IP addressing from my WinXP  network clients.  In my Dansguardian log files I can’t seem to get the user id of the student nor the actual client IP of the system they were logged into when a web page is denied.   All I get is the “gateway” masqueraded IP from the SME server, which doesn’t tell me which client system they were logged onto.

Is it possible to easily shutdown the SME Server firewall and run the server/gateway as a simple linux router between the two VLAN’s, so that the actual IP of the network client (not the server masqueraded IP) is passed through the SME server and shows up in the Dansguardian log files?

Any assistance would be appreciated.  I don’t need detailed instructions, just someone to tell me if this is easily achieved and to summarize what it would take to achieve it.  As with any customization, I know I may jeopardize the ability of the SME server to seamlessly update to new releases or security updates.

We’ve been using SME Server since version 5, and I’ve tried stopping the masquerading process, however this seems to kill all routing between the two VLANS and not just shut down the SME firewall.

Offline mmccarn

  • *
  • 2,656
  • +10/-0
Disabling firewall/masquerading in server/gateway mode ?
« Reply #1 on: June 13, 2006, 03:31:12 PM »
Why not put the student SME server in "Server Only" mode, so that that server and all student systems are connected directly to the Smoothwall, while leaving the staff system in "Server Gateway" mode to protect faculty computers from student hacking?

You'll get valid logging for all student accesses (but not from staff systems - these will all show up as coming from the faculty server...)

detspmehd

Disabling firewall/masquerading in server/gateway mode ?
« Reply #2 on: June 15, 2006, 12:29:31 AM »
I thought by putting the student server and clients on it's own VLAN, and using SME server as the "router" to the default VLAN (which goes out to the public internet) that I was isolating both staff and student VLAN's from each other and reducing the risk of a worm or trojan program blasting the entire school network and causing disruptions.   But maybe that initial approach is only a false sense of security, and with only one route to the public internet, any program which would take over one of the servers (or clients) would potentially cause disruption of the entire network throughput.

The only devices I currently have on the default VLAN are network printers and the Smoothwall firewall.  VLAN2 is the staff server and clients, while VLAN3 is the student server and clients.  I'm using Dell managed switches which don't provide layer 3 routing.  That's why I'm using the SME servers for routers to the default VLAN, which provides our network connection to the internet.

Thanks for your idea.  
That is a solution that would solve my problem and I need to consider it for simplicity sake.

Offline mmccarn

  • *
  • 2,656
  • +10/-0
Disabling firewall/masquerading in server/gateway mode ?
« Reply #3 on: June 15, 2006, 12:57:02 AM »
What about adding a couple more NICs to the smoothwall, and converting both SME servers to "Server Only" mode?

I have no experience w/ Smoothwall, so I have no idea what I'm asking...

Offline TrevorB

  • *
  • 259
  • +0/-0
    • http://www.batley.id.au
Re: Disabling firewall/masquerading in server/gateway mode ?
« Reply #4 on: June 15, 2006, 01:46:29 AM »
Quote from: "detspmehd"
The SME server operating in server/gateway mode is running a firewall which is preventing my internet firewall from receiving “ident” user information and “actual” IP addressing from my WinXP  network clients.  In my Dansguardian log files I can’t seem to get the user id of the student nor the actual client IP of the system they were logged into when a web page is denied.   All I get is the “gateway” masqueraded IP from the SME server, which doesn’t tell me which client system they were logged onto.

You could also run Dansguardian on the sme boxes, or just the Student VLAN if you want to track student access.