This article applies to our On-Premise Appliance Filter and Firewall product only, not to Cloud.
A centrally managed Smoothwall setup includes a Smoothwall running as a ‘parent’ node and one or more Smoothwall ‘child’ nodes managed by the parent. You can use this setup to standardise configuration across all nodes or have the parent monitor child nodes for updates and reporting.
Before you begin
- Ensure all nodes are updated to the same level. We recommend updating to the latest release where possible.
- Ensure you have Administrator access to all parent and child nodes.
- Check there is network access from the parent node to the child nodes:
- Go to Network > Settings > Advanced and ensure the ICMP ping checkbox in Networking features > Block and ignore is not selected.
- Ensure any firewalls between the parent and child nodes are not blocking ICMP ping traffic.
- Switch on SSH on the parent and all child nodes.
Set up central management
Step 1: Set up the parent node
- Sign in to the Smoothwall that will be the parent.
- Go to System > Central management > Settings.
- The Node role determines how this Smoothwall is used. Select Parent.
- The Node identification method determines how each child node is identified:
- Use individual node settings: Keep this selected to allow each individual node to use its own IP address or hostname.
- All nodes use the hostname: Select this option to enter a specific hostname instead of the individual node's hostname for redirect requests. This overrides the hostname in System > Preferences > Hostname.
- In the Manage central management keys section, select Download.
- Select Save.
- Sign out of the parent node.
Step 2: Set up the child node
- Sign in to a Smoothwall that will be a child.
- Go to System > Central management > Settings.
- For Node role, select Child.
- To import the Parent’s key, select Choose file.
- Find the file.
- Select Save.
- Reboot the child node.
- Sign out of the child node.
- Repeat for each child node.
Step 3: Link the child node and parent nodes
- Sign in to the Smoothwall that will be the parent.
- Go to System > Central management > Child nodes.
- Add the child nodes:
Monitor your nodes
Check node statuses
You can monitor your child nodes from the System > Central management > Overview page on the parent node. Review the Status column:
- Green tick: The node is functioning.
- Red cross: The node needs immediate attention.
- Orange exclamation mark: Check the node for potential problems.
Select the Status text to open the node’s details page.
Reboot or refresh a node
You may need to reboot a node after updating the node. You can also reboot the Smoothwall you are signed into from the Shutdown page.
- Go to System > Central management > Overview.
- Select the Status for the node you want to reboot or refresh.
- Select Refresh node to check for new updates.
- Select Reboot node to restart the node:
- Select Now to immediately update the node.
- Select Later and select the time from the drop-down to update later.
Note
If the scheduled time has passed today, the update will occur tomorrow at the selected time.
- Select Schedule reboot.
Disconnect and reconnect a node
To temporarily stop the parent from applying replication settings to a child node, disconnect the child node.
- Sign in to the child node.
- Go to System > Central management > Settings.
- Change Node role to Disabled (not centrally managed).
- Select Save.
- Make the required changes to the child node.
Tip
While disconnected, the child node will say Node not contactable on the parent node’s System > Central management > Overview page.
- Change the Node Role back to Child.
- Select Save.