chazzy2501 Posted May 11, 2015 Posted May 11, 2015 I have a bad DNS result and no amount of flushing or otherwise will fix it. Its only 1 address sslfilter.staffproxy.swgfl.org.uk it keeps resolving to 213.18.249.19 which is wrong. it needs to resolve to .18 How do I do this with AD DNS? cheers
Steve21 Posted May 11, 2015 Posted May 11, 2015 flush should do it, but don't forget it's on your DCs and client, as it'll ask DC etc first Steve
chazzy2501 Posted May 11, 2015 Author Posted May 11, 2015 @Steve21 I think the external DNS has the bad record. No amount of flushing and resetting clients, DNS servers. clears the issue.
Steve21 Posted May 11, 2015 Posted May 11, 2015 Although we haven't hit the switch yet ours seems to point to the right bit currently ping sslfilter.staffproxy.swgfl.org.uk Pinging staffproxy.swgfl.org.uk [213.18.249.18] with 32 bytes of data: Steve
localzuk Posted May 11, 2015 Posted May 11, 2015 You've got 2 options: 1. Speak to the provider of the external DNS. When I did the SWGfL SSL proxy change over, I had to speak to our LEA to fix their DNS servers as there were issues here too. 2. Add a zone to your local DNS servers called "swgfl.org.uk" and add a subdomain of sslfilter.staffproxy that is an A record pointing to the correct IP. Option 1 is the best option.
chazzy2501 Posted May 11, 2015 Author Posted May 11, 2015 yes, if I ping staffproxy.swgfl.org.uk I get .18 but if I add the sslfilter.staffproxy.swgfl.org.uk I get .19 (Which make sense, as I can't see how the server would determine what I typed in to get the address?) @Steve21 if you use the the SSLfilter proxy do you get bad RM certificates from google and the suck like? (which you should if you've not installed the RM certificate)
SchoolsBroadband Posted May 11, 2015 Posted May 11, 2015 you could also change your hosts file to test it works quickly
Boredguy Posted May 11, 2015 Posted May 11, 2015 We are resolving sslfilter.staffproxy to .18 happily over here, and we didn't have to kick the grid for it to take effect. However it does sound like an upstream DNS error. Have you tested it by changing a client from using the local DNS to the SWGfL DNS direct?
chazzy2501 Posted May 11, 2015 Author Posted May 11, 2015 @localzuk I maybe don't understand how the swgfl filtering works I think they're fudging something maybe I don't know enough? How as I said above would the proxy server know what DNS entry I used to get it's address. It makes total sense that (sslfilter.) should Point to .19 for SSL intercepts. How could the proxy server know what I typed in to get it's address (as sslfilter.staffproxy and staffproxy are supposedly supposed to point to the same ipaddress and as this is resolved locally then determine whether I should have my SSL traffic intercepted? is their a DNS mechanism I'm unaware of?
chazzy2501 Posted May 11, 2015 Author Posted May 11, 2015 @Boredguy yes we changed my workstation to the swgfl DNS servers .213 and .214 I think. Still resolves .19 (yes we flushed) Has anyone using the sslfilter checked to see whether SSLinterception is happening? Go to gmail and see the RM certificate? as that did work for me.
Boredguy Posted May 11, 2015 Posted May 11, 2015 Don't get the RM certificate at any site and we've had SSLFiltering configured since Jan
localzuk Posted May 11, 2015 Posted May 11, 2015 @localzuk I maybe don't understand how the swgfl filtering works I think they're fudging something maybe I don't know enough? How as I said above would the proxy server know what DNS entry I used to get it's address. It makes total sense that (sslfilter.) should Point to .19 for SSL intercepts. How could the proxy server know what I typed in to get it's address (as sslfilter.staffproxy and staffproxy are supposedly supposed to point to the same ipaddress and as this is resolved locally then determine whether I should have my SSL traffic intercepted? is their a DNS mechanism I'm unaware of? The proxy server will be determining it by the name used. So even if the servers are actually the same boxes with the same IP (or more likely, the proxy servers sit behind a load balancer which is sat at .18, which is figuring out if it is sslfilter or not), the servers behave differently. You need to speak to the upstream DNS provider. SSL interception isn't happening yet as far as I know, as Google hasn't set up their side. We've had it all set up and ready to go for a couple of months.
chazzy2501 Posted May 11, 2015 Author Posted May 11, 2015 @localzuk I still don't get it? DNS is resolved locally (apart from the first time) how would the proxy or the load balancer determine how I obtained the ipaddress and whether to apply SSL interception or not. SSL intercept has worked for us, I would go to gmail and I could see the RM certificate.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now