Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Setting up Sonicpoints

Posted on 2014-10-28
4
Medium Priority
?
183 Views
Last Modified: 2015-01-15
Have a location that has a sonicwall controlling 6 sonicpoints ap's.  They are installing a web filter (iprism) to block access to certain sites and run reporting.  The problem is that with the current setup, the sonicwall wireless clients aren't getting filtered.  The filter is deployed "inline" (switch->web filter->sonicwall).  The filter vendor said that since the wireless subnet isn't connected physically to the network, traffic can't be filtered unless we put the filter outside the firewall (which then you lose AD integration, etc).  

Is there a way to set up the sonicpoints where they would be connected to the physical network and be able to be filtered?  I was thinking of buying another sonicwall just to act as the wireless controller and put it behind the existing firewall but that seems like overkill.
0
Comment
Question by:jasp101
  • 2
4 Comments
 
LVL 20

Expert Comment

by:carlmd
ID: 40410484
It is not clear from you description where you have the web filter. Is it on the LAN or WAN side of the Sonicwall?

If on the WAN side, it should be filtering all traffic. If on the LAN side, it will only filter the traffic on the "X" interface that it is connected to. Typically the wireless is connected to a separate X interface, and that would be your issue.

Does the wireless have unrestricted access to the LAN?
0
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 2000 total points
ID: 40416122
In your setup, with the sonicpoints terminating at the sonicwall, the iprism needs to be on the wan side of the sonicwall. It's easy enough to allow the iprism access to AD inside your LAN. Make a service group for iprism access, make access objects for what it needs to talk to, make those into a group. Then it's just a firewall rule to allow the iprism with those services to that group of computers inside the lan. You might also need a nat rule, it's been awhile since I did this manually, I usually just use the public server wizard and make changes to what it creates.

That said, you could get another sonicwall just to terminate the sonicpoints to inside the lan inside the iprism
0
 
LVL 1

Author Comment

by:jasp101
ID: 40416131
The filter is behind the sonicwall on the LAN.  The wireless does have access to the LAN, but the only way to get the wireless to filter is to add a proxy since they are not physically on the lan.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40416460
Sonicwall has an "Automatic Proxy Forwarding (Web Only)" however the problem is:
"the proxy server must be on the wan or dmz, it cannot be on the lan"
http://help.mysonicwall.com/sw/eng/266/ui1/6600/Advanced/Proxy_Relay.htm

I suppose you could make a nat rule that all port 80 requests from the wlan go to the iprism...
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
The Summer 2017 Scholarship Winners have been announced!
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question