Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Internet Related/Filtering/Firewall

Internet Related forum sponsored by
Internet Related Forum Sponsored by Smoothwall

Woes with your internet connection or maybe having filtering issues (that are not security related) post them here.

Go Back   EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 09-11-2009, 09:41 PM   #1
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default Smoothwall content filter with bluesocket wireless

Hello people,

as the title suggests we have a smoothwall content filter and we are also using a bluesockt wireless setup.

What I want to know id if anyone has setup thier smoothwall to allow bluesocket web access but still have it filtered?

OUr setup is as follows:

BlueSocket : LDAP / Radius authentication using web portal for login information or machine based authentication.

Smoothwall : LDAP / AD authentication (not at the office but I think ident with terminal services)

I can get the wireless clients to connect to the network and authenticate no problem this issue is that a username and password is NOT being password to the smoothwall and content filtering fails so user are unable to browse.

How to setup smoothwall so that the wireless clients can surf the web but still be filtered?

Answers on a post card please......
  Reply With Quote
Old 09-11-2009, 09:57 PM   #2
 
Ric_'s Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 7,028
uk uk lancashire
Thanks: 74
Thanked 481 Times in 368 Posts
Rep Power: 109 Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute
Send a message via MSN to Ric_ Send a message via Skype™ to Ric_
Default

It works for me... my users are using NTLM pass-thru to AD authentication. Mobile Gaurdian is now being used to set proxy details too.

Of course, these are managed computers. I've got to set up the whole captive-portal style thing and I'm leaning towards AD auth through a web page... the users will then get passed to a VLAN which I'll put through a specific port on my UTM and just filter ALL the traffic.
  Reply With Quote
Old 10-11-2009, 08:41 AM   #3
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set?
  Reply With Quote
Old 10-11-2009, 10:07 AM   #4
 
ssiruuk2's Avatar
 
Join Date: Feb 2008
Posts: 233
uk
Thanks: 11
Thanked 38 Times in 30 Posts
Rep Power: 12 ssiruuk2 has a spectacular aura about ssiruuk2 has a spectacular aura about ssiruuk2 has a spectacular aura about
Default

Quote:
Originally Posted by ICTNUT View Post
Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set?
If your using ident in terminal services compat mode aren't you already using NTLM ?

If your wirless users are on unmanaged machines you will have to use either the ssl login page option or rely on the pop up window that the smoothwall will give your users if it can't authenticate them automatically. I found both these worked fine with Windows clients but Mac did not get on well at all (SSL login didn't work and the pop up window was a bit flakey sometimes repeatedly asking for credentials when clicking on links) - for now our guest wirless are not authenticated as a result.
  Reply With Quote
Old 10-11-2009, 10:41 AM   #5
 
Ric_'s Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 7,028
uk uk lancashire
Thanks: 74
Thanked 481 Times in 368 Posts
Rep Power: 109 Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute
Send a message via MSN to Ric_ Send a message via Skype™ to Ric_
Default

Quote:
Originally Posted by ICTNUT View Post
Ric_: Where are you setting the NTLM pass-thru as I am sure if I can do this it will all work also but I must be blind as I cannot see where it is set?
On your Bluesecure controller, go to 'User Authentication' -> 'Authentication Server' -> 'Create... Transparent NTLM Windows Authentication'

Fill in the relevant domain controller details and in the drop down box named 'or using LDAP/Active Directory server' simply select your AD authentication settings.

It's all in the BlueSocket training materials that are available off the support pages of their website (along with lots of other good stuff ).
  Reply With Quote
Thanks to Ric_ from:
ICTNUT (11-11-2009)
Old 11-11-2009, 09:34 AM   #6
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Quote:
Originally Posted by Ric_ View Post
It works for me... my users are using NTLM pass-thru to AD authentication. Mobile Gaurdian is now being used to set proxy details too.

Of course, these are managed computers. I've got to set up the whole captive-portal style thing and I'm leaning towards AD auth through a web page... the users will then get passed to a VLAN which I'll put through a specific port on my UTM and just filter ALL the traffic.
I have setup AD (transparent NTLM) auth through the SSL web page on the bluesocket and authentication works (these are unmanaged laptops and mobile devices).

On the status page for the bluesocket I can see the users that have authenticated but they cannot surf, Smoothwall is still coming back with unknown username or password and tries to stick them in the unatuhenticated users which I have setup as a default block everything.

See that the bluesocket bit is ok I will assume that there is still something I need to do on the smoothwall....

Last edited by ICTNUT; 11-11-2009 at 09:38 AM.. Reason: typo
  Reply With Quote
Old 11-11-2009, 09:51 AM   #7
 
Ric_'s Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 7,028
uk uk lancashire
Thanks: 74
Thanked 481 Times in 368 Posts
Rep Power: 109 Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute
Send a message via MSN to Ric_ Send a message via Skype™ to Ric_
Default

Are you using the Smoothie as a transparent proxy? IIRC a transparent proxy cannot authenticate users.

This is why I plan to do it the why I describe above. Dump the unmanaged devices onto a different VLAN with only access to the Smoothie box and then tell Smoothie to act as a transparent proxy on that VLAN, applying a strict filtering policy.
  Reply With Quote
Old 11-11-2009, 10:20 AM   #8
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Quote:
Originally Posted by Ric_ View Post
Are you using the Smoothie as a transparent proxy? IIRC a transparent proxy cannot authenticate users.

This is why I plan to do it the why I describe above. Dump the unmanaged devices onto a different VLAN with only access to the Smoothie box and then tell Smoothie to act as a transparent proxy on that VLAN, applying a strict filtering policy.
Nope not using smootie as a transparent proxy, using NTLM Identification (Terminal Services compatibility mode)

So my next question would be how do you have the smoothie setup with more than one authentication method?

We do want to be able to log all the kids and thier access and would like to do the same for the wireless access but if that is not possible just making sure that the wirless internet access is filtered (strict) would suffice.
  Reply With Quote
Old 12-11-2009, 12:17 AM   #9
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 1,958
uk uk yorkshire
Thanks: 171
Thanked 260 Times in 194 Posts
Rep Power: 59 tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of tom_newton has much to be proud of
Default

Oz, you can only use a single authtype at the moment (though this is changing).

Call me (back Friday) or RobF (0113 3874181, in Tomorrow all day AFAIK) and we'll have a poke about.
  Reply With Quote
Thanks to tom_newton from:
ICTNUT (12-11-2009)
Old 12-11-2009, 09:53 AM   #10
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Will do :-)
  Reply With Quote
Old 12-11-2009, 09:57 AM   #11
 
Ric_'s Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 7,028
uk uk lancashire
Thanks: 74
Thanked 481 Times in 368 Posts
Rep Power: 109 Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute
Send a message via MSN to Ric_ Send a message via Skype™ to Ric_
Default

@ICTNUT: If the users are on unmangaed machines, will NTLM (or other types of) authentication work?

If Smoothie acts as a transparent proxy, you will log all the IPs of the users and you can cross reference that with your ClueSocket logs. A PITA but you can still find those little darlings that are looking for pr0n.
  Reply With Quote
Old 12-11-2009, 10:43 AM   #12
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Quote:
Originally Posted by Ric_ View Post
@ICTNUT: If the users are on unmangaed machines, will NTLM (or other types of) authentication work?

If Smoothie acts as a transparent proxy, you will log all the IPs of the users and you can cross reference that with your ClueSocket logs. A PITA but you can still find those little darlings that are looking for pr0n.
Hmm thats a good point, I have a script that runs which will only allow a single logon instance for any student or staff with the time, date, IP, and pc name being logged to a central database so finding out who did what is not really going to be that much of an issue.

I will have a play and let you know.
  Reply With Quote
Old 12-11-2009, 10:45 AM   #13
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Where on the smoothie do we set transparent proxy then......?
  Reply With Quote
Old 12-11-2009, 10:57 AM   #14
 
Ric_'s Avatar
 
Join Date: Jun 2005
Location: Lancashire
Posts: 7,028
uk uk lancashire
Thanks: 74
Thanked 481 Times in 368 Posts
Rep Power: 109 Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute Ric_ has a reputation beyond repute
Send a message via MSN to Ric_ Send a message via Skype™ to Ric_
Default

Quote:
Originally Posted by ICTNUT View Post
Where on the smoothie do we set transparent proxy then......?
Gaurdian -> Web Proxy

Just give me remote access to your systems and I'll set it up for you shall I?
  Reply With Quote
Old 12-11-2009, 11:08 AM   #15
 
ICTNUT's Avatar
 
Join Date: Jul 2005
Location: Hereford
Posts: 1,052
uk uk wales
Thanks: 103
Thanked 167 Times in 58 Posts
Rep Power: 39 ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold ICTNUT is a splendid one to behold
Default

Error - NTLM in Terminal Services compatibility mode cannot be used with 'Transparent' enabled

Which one should I set it to then?

Ident by IP??
  Reply With Quote
Reply

EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall

Similar Threads
Thread Thread Starter Forum Replies Last Post
Smoothwall Web Content Filter Problem trekmad Internet Related/Filtering/Firewall 8 15-03-2009 08:53 AM
Advice needed on content filter setup netadmin Networks 5 21-05-2008 02:43 PM
VMWare internet content filter server netadmin *nix 3 30-05-2007 08:12 AM
Setting up Dansguardian content filter on smoothwall box. tickmike *nix 13 04-10-2006 10:42 AM



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:15 PM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
SERVER: 4
no new posts