Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

*nix Powering the backend of many of our networks, unbeknown to many. Linux, Solaris, Unix...

Go Back   EduGeek.net Forums > Technical > *nix
Reply
 
LinkBack Thread Tools Search this Thread Language
Sponsored Links
Old 24-07-2008, 07:33 PM   #1 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default School Guardian 2008 and ntlm

I've spent the last couple of days trying to get School Guardian 2008 installed and configured. I've found lots of nice things in it!

However I have hit a rather nasty problem. I can't get ntlm authentication/identification to work correctly.

Does anyone else use this combination successfully?

As it stands this is whats happening

User authenticates. Page is requested. Some of the page comes back. I've been talking to support who have helped a bit with the issue (turning on persistant connections seems to help quite a bit) but I've not been able to eliminate it. The content is not currently being filtered.

I've been working on it tonight as I'm really pushed for time. One interesting thing I did note is that some items appear in the filter request log *exactly* 2 minutes after the original requests. This doesn't seem to happen with no auth, ssl auth or any of the others I would assume.

Using safari seems to exacerbate the issue, often losing the page style sheets.
  Reply With Quote
Old 24-07-2008, 09:31 PM   #2 (permalink)
 
edsa's Avatar
 
Join Date: Apr 2007
Location: Northumberland
Posts: 37
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0 edsa is an unknown quantity at this point
edsa is offline
Default

Quote:
Originally Posted by DMcCoy View Post
I've spent the last couple of days trying to get School Guardian 2008 installed and configured. I've found lots of nice things in it!

However I have hit a rather nasty problem. I can't get ntlm authentication/identification to work correctly.

Does anyone else use this combination successfully?

As it stands this is whats happening

User authenticates. Page is requested. Some of the page comes back. I've been talking to support who have helped a bit with the issue (turning on persistant connections seems to help quite a bit) but I've not been able to eliminate it. The content is not currently being filtered.

I've been working on it tonight as I'm really pushed for time. One interesting thing I did note is that some items appear in the filter request log *exactly* 2 minutes after the original requests. This doesn't seem to happen with no auth, ssl auth or any of the others I would assume.

Using safari seems to exacerbate the issue, often losing the page style sheets.
We had a similar problem when we first installed School Guardian. A workround was to enable ntlm identification (terminal services compat mode) This seemed to do the trick until Smoothwall released an upgrade to fix the problem. We now use ntlm ident with no problems

Make sure that filtering is applied to the user groups that you wish to filter.

Have you tried a save and restart with cleared cache?
  Reply With Quote
Old 24-07-2008, 09:46 PM   #3 (permalink)
 
GrumbleDook's Avatar
 
Join Date: Jul 2005
Location: Kettering, Northants
Posts: 4,688
ireland uk england
Thanks: 44
Thanked 118 Times in 82 Posts
Blog Entries: 1
Rep Power: 37 GrumbleDook is a splendid one to beholdGrumbleDook is a splendid one to beholdGrumbleDook is a splendid one to beholdGrumbleDook is a splendid one to beholdGrumbleDook is a splendid one to beholdGrumbleDook is a splendid one to behold
GrumbleDook is online now Send a message via AIM to GrumbleDook Send a message via MSN to GrumbleDook Send a message via Yahoo to GrumbleDook Send a message via Skype™ to GrumbleDook
Default

We are using Network Guardian and have also been on the phone tonight with Nick about a similar issue.

The above fix also worked for us.
  Reply With Quote
Old 25-07-2008, 12:17 AM   #4 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default

Hmm, seems to be something a bit like this

'[squid-users] Squid sends TCP_DENIED/407 even on already authenticated users' - MARC

In fact on the wikipedia front page I had no formating, and there was a 407 for the main.css file amongst lots of 200s.
  Reply With Quote
Old 25-07-2008, 12:37 AM   #5 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default

The 407 itself is ok, it seems that while IE mostly retries and is successful, Safari often doesn't retry or fails.

I would blame OS X and ntlm but I've not been able to replicate the issue using ntlm to an ISA proxy. I'll have a go with 10.4 tomorrow anyway.
  Reply With Quote
Old 25-07-2008, 10:21 AM   #6 (permalink)
 
ahuxham's Avatar
 
Join Date: Apr 2008
Location: Somerset
Posts: 235
Thanks: 11
Thanked 12 Times in 12 Posts
Rep Power: 3 ahuxham will become famous soon enough
ahuxham is offline
Default

Sorry to de-rail, but isn't NTLM just dandy?
  Reply With Quote
Old 25-07-2008, 10:59 AM   #7 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default

Quote:
Originally Posted by ahuxham View Post
Sorry to de-rail, but isn't NTLM just dandy?
No

See attached
Attached Images
File Type: png Picture 1.png (61.9 KB, 21 views)
  Reply With Quote
Old 25-07-2008, 11:14 AM   #8 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default

Going to try ident servers on the windows and macs later instead. That should work
  Reply With Quote
Old 25-07-2008, 11:21 AM   #9 (permalink)
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 3,577
uk
Thanks: 12
Thanked 50 Times in 50 Posts
Rep Power: 21 plexer is a jewel in the roughplexer is a jewel in the roughplexer is a jewel in the rough
plexer is offline
Default

I had several issues with NLTM some users would get asked for a username/password combo via a popup box even though it's not supposed to do this.

I tried various things as suggested by tech support and I'll be looking into this again when I'm in over the hols.

Ben
  Reply With Quote
Old 25-07-2008, 11:55 AM   #10 (permalink)
 
ChrisH's Avatar
 
Join Date: Jun 2005
Location: East Lancs
Posts: 3,617
uk uk lancashire
Thanks: 1
Thanked 22 Times in 17 Posts
Rep Power: 17 ChrisH will become famous soon enoughChrisH will become famous soon enough
ChrisH is offline
Default

Quote:
Originally Posted by plexer View Post
I had several issues with NLTM some users would get asked for a username/password combo via a popup box even though it's not supposed to do this.

I tried various things as suggested by tech support and I'll be looking into this again when I'm in over the hols.

Ben
You usually only get that when they are trying to access from more than one machine or they have swopped machines and it hasnt timed out for the old machine yet.
  Reply With Quote
Old 25-07-2008, 11:59 AM   #11 (permalink)
 
OverWorked's Avatar
 
Join Date: Jul 2005
Location: N. Yorks
Posts: 535
Thanks: 32
Thanked 9 Times in 8 Posts
Rep Power: 10 OverWorked will become famous soon enough
OverWorked is offline
Default

I had a bit of trouble getting it going, but it's worked flawlessly since.

First of all, I second what Edsa said. Here's a few ideas:-

services » authentication » control - do you get all green lights?

services » authentication » settings - is it all filled in correctly? If you're using AD, I could PM you a screen shot of mine.

services » authentication » user activity - are users being listed?

system » preferences » time - is the clock correct? Timezone should be Europe/London. I just manually set my clock - I couldn't get NTP to work. The RTC in the BIOS should be set to GMT (not BST).
  Reply With Quote
Old 25-07-2008, 11:59 AM   #12 (permalink)
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 3,577
uk
Thanks: 12
Thanked 50 Times in 50 Posts
Rep Power: 21 plexer is a jewel in the roughplexer is a jewel in the roughplexer is a jewel in the rough
plexer is offline
Default

Nope definitely not that.

Ben
  Reply With Quote
Old 25-07-2008, 01:09 PM   #13 (permalink)
 
DMcCoy's Avatar
 
Join Date: Oct 2005
Location: Isle of Wight
Posts: 1,670
uk uk isle of wight
Thanks: 1
Thanked 64 Times in 59 Posts
Rep Power: 21 DMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really niceDMcCoy is just really nice
DMcCoy is online now
Default

With the persistant connections and a rebuild the 407s (without browser retries) have reduced to an acceptable level, at least with low volume testing. Just had one image not show up so far on apples home page (which was quite problematic).

Hopefully that it will work well enough to keep with ntlm, although I'll be adding ident servers to machine when I reimage
  Reply With Quote
Old 25-07-2008, 02:07 PM   #14 (permalink)
 
tom_newton's Avatar
 
Join Date: Sep 2006
Location: Leeds
Posts: 761
uk uk yorkshire
Thanks: 5
Thanked 21 Times in 19 Posts
Rep Power: 8 tom_newton will become famous soon enoughtom_newton will become famous soon enough
tom_newton is offline
Default

I would vaguely wonder about auth timeouts... but then i'd just be tinkering to "see if it does anything"

Also - if you enable/disable transparent filtering it changes the way NTLM does things (IIRC!).

We are looking at SPNEGO and all things "post" NTLM, but there aren't really many good, widely used standards for this sort of thang.
  Reply With Quote
Reply

Register now for FREE and post messages!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Image Verification
  I agree to forum rules 

Similar Threads
Thread Thread Starter Forum Replies Last Post
Forensic Software or School Guardian which one Grommit Network and Classroom Management 19 24-07-2008 12:55 PM
School Guardian tldees Networks 3 12-06-2008 05:08 PM
Network Guardian 2008 is nice. plexer How do you do....it? 0 23-04-2008 03:29 PM


Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 06:12 PM.
Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright EduGeek.net