Jump to content

Recommended Posts

Posted

I have a bad DNS result and no amount of flushing or otherwise will fix it. Its only 1 address sslfilter.staffproxy.swgfl.org.uk it keeps resolving to 213.18.249.19 which is wrong. it needs to resolve to .18 How do I do this with AD DNS?

 

cheers

Posted

Although we haven't hit the switch yet ours seems to point to the right bit currently

 

ping sslfilter.staffproxy.swgfl.org.uk

Pinging staffproxy.swgfl.org.uk [213.18.249.18] with 32 bytes of data:

 

Steve

Posted

You've got 2 options:

 

1. Speak to the provider of the external DNS. When I did the SWGfL SSL proxy change over, I had to speak to our LEA to fix their DNS servers as there were issues here too.

2. Add a zone to your local DNS servers called "swgfl.org.uk" and add a subdomain of sslfilter.staffproxy that is an A record pointing to the correct IP.

 

Option 1 is the best option.

Posted

yes, if I ping staffproxy.swgfl.org.uk I get .18 but if I add the sslfilter.staffproxy.swgfl.org.uk I get .19 (Which make sense, as I can't see how the server would determine what I typed in to get the address?)

@Steve21 if you use the the SSLfilter proxy do you get bad RM certificates from google and the suck like? (which you should if you've not installed the RM certificate)

Posted

We are resolving sslfilter.staffproxy to .18 happily over here, and we didn't have to kick the grid for it to take effect.

 

However it does sound like an upstream DNS error. Have you tested it by changing a client from using the local DNS to the SWGfL DNS direct?

Posted

@localzuk I maybe don't understand how the swgfl filtering works I think they're fudging something maybe I don't know enough? How as I said above would the proxy server know what DNS entry I used to get it's address. It makes total sense that (sslfilter.) should Point to .19 for SSL intercepts.

 

How could the proxy server know what I typed in to get it's address (as sslfilter.staffproxy and staffproxy are supposedly supposed to point to the same ipaddress and as this is resolved locally then determine whether I should have my SSL traffic intercepted? is their a DNS mechanism I'm unaware of?

Posted
@Boredguy yes we changed my workstation to the swgfl DNS servers .213 and .214 I think. Still resolves .19 (yes we flushed) Has anyone using the sslfilter checked to see whether SSLinterception is happening? Go to gmail and see the RM certificate? as that did work for me.
Posted
@localzuk I maybe don't understand how the swgfl filtering works I think they're fudging something maybe I don't know enough? How as I said above would the proxy server know what DNS entry I used to get it's address. It makes total sense that (sslfilter.) should Point to .19 for SSL intercepts.

 

How could the proxy server know what I typed in to get it's address (as sslfilter.staffproxy and staffproxy are supposedly supposed to point to the same ipaddress and as this is resolved locally then determine whether I should have my SSL traffic intercepted? is their a DNS mechanism I'm unaware of?

 

The proxy server will be determining it by the name used. So even if the servers are actually the same boxes with the same IP (or more likely, the proxy servers sit behind a load balancer which is sat at .18, which is figuring out if it is sslfilter or not), the servers behave differently.

 

You need to speak to the upstream DNS provider.

 

SSL interception isn't happening yet as far as I know, as Google hasn't set up their side. We've had it all set up and ready to go for a couple of months.

Posted

@localzuk I still don't get it? DNS is resolved locally (apart from the first time) how would the proxy or the load balancer determine how I obtained the ipaddress and whether to apply SSL interception or not.

 

SSL intercept has worked for us, I would go to gmail and I could see the RM certificate.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...