Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Setting up Sonicpoints

Posted on 2014-10-28
4
Medium Priority
?
181 Views
Last Modified: 2015-01-15
Have a location that has a sonicwall controlling 6 sonicpoints ap's.  They are installing a web filter (iprism) to block access to certain sites and run reporting.  The problem is that with the current setup, the sonicwall wireless clients aren't getting filtered.  The filter is deployed "inline" (switch->web filter->sonicwall).  The filter vendor said that since the wireless subnet isn't connected physically to the network, traffic can't be filtered unless we put the filter outside the firewall (which then you lose AD integration, etc).  

Is there a way to set up the sonicpoints where they would be connected to the physical network and be able to be filtered?  I was thinking of buying another sonicwall just to act as the wireless controller and put it behind the existing firewall but that seems like overkill.
0
Comment
Question by:jasp101
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 20

Expert Comment

by:carlmd
ID: 40410484
It is not clear from you description where you have the web filter. Is it on the LAN or WAN side of the Sonicwall?

If on the WAN side, it should be filtering all traffic. If on the LAN side, it will only filter the traffic on the "X" interface that it is connected to. Typically the wireless is connected to a separate X interface, and that would be your issue.

Does the wireless have unrestricted access to the LAN?
0
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 2000 total points
ID: 40416122
In your setup, with the sonicpoints terminating at the sonicwall, the iprism needs to be on the wan side of the sonicwall. It's easy enough to allow the iprism access to AD inside your LAN. Make a service group for iprism access, make access objects for what it needs to talk to, make those into a group. Then it's just a firewall rule to allow the iprism with those services to that group of computers inside the lan. You might also need a nat rule, it's been awhile since I did this manually, I usually just use the public server wizard and make changes to what it creates.

That said, you could get another sonicwall just to terminate the sonicpoints to inside the lan inside the iprism
0
 
LVL 1

Author Comment

by:jasp101
ID: 40416131
The filter is behind the sonicwall on the LAN.  The wireless does have access to the LAN, but the only way to get the wireless to filter is to add a proxy since they are not physically on the lan.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40416460
Sonicwall has an "Automatic Proxy Forwarding (Web Only)" however the problem is:
"the proxy server must be on the wan or dmz, it cannot be on the lan"
http://help.mysonicwall.com/sw/eng/266/ui1/6600/Advanced/Proxy_Relay.htm

I suppose you could make a nat rule that all port 80 requests from the wlan go to the iprism...
0

Featured Post

ATEN's HDBaseT Presentation at InfoComm 2017

Hear ATEN Product Manager YT Liang review HDBaseT technology, highlighting ATEN’s latest solutions as they relate to real-world applications during her presentation at the HDBaseT booth at InfoComm 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question