Some features present in the Maiden version of the On-Premise Appliance are not available in Newport. You must turn off these features before upgrading to Newport.
Before you begin
- You must have Administrator access to Smoothwall.
- Ensure you’ve updated to the latest Maiden release. You cannot directly update from Leeds to Newport.
- If you’re using an Active Directory directory type, you must switch to using the IDex directory type. This will handle the login events from your Active Directory Server.
- Become familiar with Smoothwall’s guidance for updating your On-Premise Appliance.
Warning
Updating to Newport may take some time, depending on your hardware. To prevent damage, do not turn off the Appliance until the upgrade is complete.
Fix blockers for Newport updates
Legacy Auth Methods
Go to Web Proxy > Authentication > Manage Policies and ensure Core Authentication is selected (not any NTLM or Kerberos methods) if you’re moving to IDex for authentication or RADIUS accounting.
For more information, see: Authentication Methods.
Kerberos keytabs
Go to Services > Authentication > Kerberos Keytabs and ensure all keytab entries have been deleted, not just turned off.
Legacy Directories
In Services > Authentication > Directories, ensure all Active Directory entries have been deleted, not just turned off.
Note
You must switch to using the IDex directory type. This will handle the login events from your Active Directory Server
Legacy IPSec security
- In Network > VPN > IPSec Subnets, go to Advanced options and ensure the following configurations (even if not turned on):
- IKEv2 is selected.
- Authentication type is ESP.
- The cryptographic algorithm is at least AES128 (AES256 preferred).
- Hash algorithm is SHA2
- Diffie-Hellman group is 14 or 19
-
In Network > VPN > Global, ensure Enable IKEv2 client VPN is not selected.
Note
When changing your VPN configurations, make sure to update your VPN tunnel settings as well, so both configurations match.
Legacy Auth Smoothwall Access
In Network > Firewall > Smoothwall Access, ensure the Kerberos port (814) is not allowed.
Legacy VPN security
In Network > VPN > Global, ensure Enhanced VPN Security is selected, and any clients are updated with the new archive.
User portal
This feature is deprecated in Newport. Please speak to your Customer Success Manager for help with Cloud Filter access.
Unsupported features
Web Proxy
- Go to Web Proxy > Auth Methods and turn off:
- Global Proxy using NTLM
- Kerberos
- Kerberos Terminal Services
- Kerberos via Redirect
- NTLM Authentication
- NTLM Authentication Terminal Services
- NTLM Authentication via Redirect
- NTLM Identification
- NTLM Identification Terminal Services
- NTLM Identification via Redirect
- Negotiate NTLM/Kerberos
- Negotiate NTLM/Kerberos Terminal Services
- Negotiate NTLM/Kerberos via Redirect
- Go to Global Proxy and turn off Global Proxy using NTLM. If you use Global Proxy, we recommend switching to Cloud Filter.
Services
-
Go to Services > Authentication Directories and turn off RADIUS Authentication.
Note
While the Appliance itself doesn't require further updates, you must reconfigure your access point to perform RADIUS authentication directly against a directory server (like Active Directory).
- Go to Services > Proxies > Reverse Proxy. Ensure the Reverse Proxy module is uninstalled in System > Modules.
- Go to Services > Intrusion System and turn off IDS/IPS.
Planned features
Newport does not currently support these features, but we plan to include them in upcoming releases.
- Clustering (Parent/Child) - Newport-12
- DHCP (Relay) - Newport-12
- IDS/IPS - TBC
Next steps
Once you turn off your On-Premise Maiden features, you can: