![]() | Register | FAQ | Members | Social Groups | User Map | Calendar | Search | Today's Posts | Mark Forums Read |
Internet Related/Filtering/Firewall Internet Related forum sponsored by |
| ||
| | | LinkBack | Thread Tools | Search Thread |
| Sponsored Links |
| | #1 |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | as the title suggests we have a smoothwall content filter and we are also using a bluesockt wireless setup. What I want to know id if anyone has setup thier smoothwall to allow bluesocket web access but still have it filtered? OUr setup is as follows: BlueSocket : LDAP / Radius authentication using web portal for login information or machine based authentication. Smoothwall : LDAP / AD authentication (not at the office but I think ident with terminal services) I can get the wireless clients to connect to the network and authenticate no problem this issue is that a username and password is NOT being password to the smoothwall and content filtering fails so user are unable to browse. How to setup smoothwall so that the wireless clients can surf the web but still be filtered? Answers on a post card please...... |
| |
| | #2 |
![]() | It works for me... my users are using NTLM pass-thru to AD authentication. Mobile Gaurdian is now being used to set proxy details too. Of course, these are managed computers. I've got to set up the whole captive-portal style thing and I'm leaning towards AD auth through a web page... the users will then get passed to a VLAN which I'll put through a specific port on my UTM and just filter ALL the traffic. |
| |
| | #3 |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set? |
| |
| | #4 | |
![]() Join Date: Feb 2008
Posts: 233
Thanks: 11
Thanked 38 Times in 30 Posts
Rep Power: 12 | Quote:
If your wirless users are on unmanaged machines you will have to use either the ssl login page option or rely on the pop up window that the smoothwall will give your users if it can't authenticate them automatically. I found both these worked fine with Windows clients but Mac did not get on well at all (SSL login didn't work and the pop up window was a bit flakey sometimes repeatedly asking for credentials when clicking on links) - for now our guest wirless are not authenticated as a result. | |
| |
| | #5 | |
![]() | Quote:
Fill in the relevant domain controller details and in the drop down box named 'or using LDAP/Active Directory server' simply select your AD authentication settings. It's all in the BlueSocket training materials that are available off the support pages of their website (along with lots of other good stuff | |
| |
| Thanks to Ric_ from: | ICTNUT (11-11-2009)
|
| | #6 | |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Quote:
On the status page for the bluesocket I can see the users that have authenticated but they cannot surf, Smoothwall is still coming back with unknown username or password and tries to stick them in the unatuhenticated users which I have setup as a default block everything. See that the bluesocket bit is ok I will assume that there is still something I need to do on the smoothwall.... Last edited by ICTNUT; 11-11-2009 at 09:38 AM.. Reason: typo | |
| |
| | #7 |
![]() | Are you using the Smoothie as a transparent proxy? IIRC a transparent proxy cannot authenticate users. This is why I plan to do it the why I describe above. Dump the unmanaged devices onto a different VLAN with only access to the Smoothie box and then tell Smoothie to act as a transparent proxy on that VLAN, applying a strict filtering policy. |
| |
| | #8 | |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Quote:
So my next question would be how do you have the smoothie setup with more than one authentication method? We do want to be able to log all the kids and thier access and would like to do the same for the wireless access but if that is not possible just making sure that the wirless internet access is filtered (strict) would suffice. | |
| |
| | #9 |
![]() Join Date: Sep 2006 Location: Leeds
Posts: 1,958
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 | Oz, you can only use a single authtype at the moment (though this is changing). Call me (back Friday) or RobF (0113 3874181, in Tomorrow all day AFAIK) and we'll have a poke about. |
| |
| Thanks to tom_newton from: | ICTNUT (12-11-2009)
|
| | #10 |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Will do :-) |
| |
| | #11 |
![]() | @ICTNUT: If the users are on unmangaed machines, will NTLM (or other types of) authentication work? If Smoothie acts as a transparent proxy, you will log all the IPs of the users and you can cross reference that with your ClueSocket logs. A PITA but you can still find those little darlings that are looking for pr0n. |
| |
| | #12 | |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Quote:
I will have a play and let you know. | |
| |
| | #13 |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Where on the smoothie do we set transparent proxy then......? |
| |
| | #14 |
![]() | |
| |
| | #15 |
![]() Join Date: Jul 2005 Location: Hereford
Posts: 1,052
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 | Error - NTLM in Terminal Services compatibility mode cannot be used with 'Transparent' enabled Which one should I set it to then? Ident by IP?? |
| |
| | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Smoothwall Web Content Filter Problem | trekmad | Internet Related/Filtering/Firewall | 8 | 15-03-2009 08:53 AM |
| Advice needed on content filter setup | netadmin | Networks | 5 | 21-05-2008 02:43 PM |
| VMWare internet content filter server | netadmin | *nix | 3 | 30-05-2007 08:12 AM |
| Setting up Dansguardian content filter on smoothwall box. | tickmike | *nix | 13 | 04-10-2006 10:42 AM |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search Thread |
| |










