Internet Related/Filtering/Firewall Thread, Netsweeper - Tearing my hair out in Technical; Evening,
Not sure anyone can help but I'll cross my fingers.
Here we go.... for the past two/three years the ...
-
1st February 2012, 08:29 PM #1 Netsweeper - Tearing my hair out
Evening,
Not sure anyone can help but I'll cross my fingers.
Here we go.... for the past two/three years the LEA have been using Netsweeper as their preferred filtering solution. It was put in to replace Websense which wasn't really doing the job. So the LEA and Netsweeper cobbled together something and all was good. From what I gather it was put behind an ISA box and a special plug-in written. This plug-in kept crashing due to memory leaks and the LEA started looking for something else.
They have now moved over to the Squid version of Netsweeper and it isn't working properly. Browsing the web is fine in IE and Firefox but the moment you want to use a plug in such as Java (e.g. to access yousrc.com ) or if you want to use a piece of software such as iTunes or gotomeeting then you are immediately challenged with an authentication box (see picture attached). The LEA are at a loss. Entering credentials are not working.
I've contacted Netsweeper and they have asked for the squid.conf file - which I do not have as I don't have access to the Netsweeper boxes.
Has anyone seen this before? Would anyone have any idea what changes I could ask the LEA to make? It's affecting lessons as we cannot teach our Java lesson (again using yousrc.com). I've asked the LEA for the squid.conf file but I very much doubt they would give it to me. Netsweeper (in their defence) are helping me even though the support contract is with the LEA. I'm bypassing the normal channels because nothing is happening.
If anyone has any ideas I'd love to here them.
Many thanks
Garethtony.jpg
-
-
IDG Tech News
-
1st February 2012, 08:35 PM #2
- Rep Power
- 0
I've seen things vaguely similar, in particular with iTunes. The addresses/URLs needed adding to the Default Subnet Policy, as well as the Staff/Student policy as it was trying to authenticate to the NetSweeper as the machine rather than the user. It's been a while since I've dealt with it though.
-
Thanks to Jonah from:
garethedmondson (2nd February 2012)
-
1st February 2012, 08:37 PM #3 
Originally Posted by
Jonah
I've seen things vaguely similar, in particular with iTunes. The addresses/URLs needed adding to the Default Subnet Policy, as well as the Staff/Student policy as it was trying to authenticate to the NetSweeper as the machine rather than the user. It's been a while since I've dealt with it though.
Not entirely sure what you mean. I've added some of the urls to the allow policy. *.yousrc.com etc - still isn't working.
Gareth
-
-
1st February 2012, 10:13 PM #4 Java doesn't play nice with proxy authentication, in general. Would suggest the LEA need to exclude those domains from being authenticated. It is not a hard thing to do in squid, and if netsweeper can't help them fix it...
-
Thanks to tom_newton from:
garethedmondson (2nd February 2012)
-
1st February 2012, 10:49 PM #5 I'm guessing you're using Kerberos?
OK, unless you get NTLM + basic authentication working (and as it happens I'm working on that problem with Squid), you can allow an exception in your squid.conf for java.
I'll post the exception tomorrow. It works for itunes, too.
Be careful doing this though, I'll explain by PM if you like as there's a massive security hole.
Last edited by jinnantonnixx; 1st February 2012 at 10:51 PM.
-
Thanks to jinnantonnixx from:
garethedmondson (2nd February 2012)
-
2nd February 2012, 12:44 PM #6
- Rep Power
- 0
Hi Gareth, can you PM me your details and we will get this resolved? We've been running NTLM and Kerberos authentication in other regions. No doubt we'll have to go back to the LA with it however that's no big issue wf we know what the challenge is.
James
-
-
2nd February 2012, 12:52 PM #7 You could try this in your squid.conf
acl AgentsNoAuth browser Java/ iTunes NSPlayer/
http_access allow AgentsNoAuth
then further down where you have your re-writes:
url_rewrite_access deny AgentsNoAuth
Edit: I've just re-read your post and you say you don't have access to the squid config. I don't know what to suggest in this case. I don't think there's anything you can do at your end.
Last edited by jinnantonnixx; 2nd February 2012 at 01:07 PM.
-
SHARE:
Similar Threads
-
By swpmre in forum Windows Server 2008
Replies: 16
Last Post: 15th September 2011, 08:44 AM
-
By jgcracknell in forum Virtual Learning Platforms
Replies: 6
Last Post: 18th April 2011, 01:05 PM
-
By FragglePete in forum Virtual Learning Platforms
Replies: 21
Last Post: 20th September 2010, 07:58 PM
-
By Talorin in forum General Chat
Replies: 13
Last Post: 29th June 2009, 09:26 AM
-
By sidewinder in forum Mac
Replies: 2
Last Post: 4th November 2008, 11:34 AM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules