Jump to content

Recommended Posts

Posted

Alright, so we've had a situation, which has made us go down the route of disabling the internet for one user. Proxy settings for smoothwall are pushed out via Group Policy and not changeable for students. I've put the user in question in a filter policy to block the 'everything' category.

 

When I've tried to log in to the students account on the computer I couldn't access anything on the internet (I get a proxy connection failed error) and couldn't change the proxy settings. But I've been stood watching him access BBC bitesize and games on Chrome. Then when I tried again 5 seconds after I got the same error.

 

 

I'm at a total loss as to how he's managed it, any help would be brilliant!

Posted

The interface we use for the proxy for students accounts uses NTLM authentication... I've never had trouble with Chrome authenticating in the past. How can I check it isn't being bypassed? I presume it must be authenticating and putting the students into the right group seen as the account I'm blocking everything for is the one I'm getting proxy errors on, as if Smoothwalls just refusing the connection?

 

We have an authentications exceptions category, but that only contains the Office 365 domains and the policy is way further down the hierarchy than the Block everything for the specific student?

 

The only other way I'm aware of to bypass authentication is by using a different proxy port which is set to just authenticate as staff, but it's only used on staff devices.

Posted
Are you able to check the log for the computer that was used? If so you will be able to see what user was used to access the BBC web site.
Guest obsidianpillar
Posted

He may have the Smoothwall Admin credentials? Previously, some organisations I've seen have the same password throughout their network for authentication. In one instance a business stored their Domain Admin password in their MDT Deployment Settings and it was the same password for everything. I'd look at the background with the student, is he computer literate beyond his age group? Do you have any auditing software that would be able for trace this and thus you would be able to understand what he's doing? You could block Chrome using a Software Restriction Policy inside of a GPO and force him to use IE? That way the proxy settings would propagate. I'm not too literate with Smoothwall (more Sophos) but seeing the proxy settings inside of a GPO 127.0.0.1 should surely stop everything? That's what I do with certain users in our environment that require the internet disabled in all cases the default proxy settings for IE propagate to Chrome unless configured differently with the ADM files.

 

Let me know if you find out the eventual cause. I, like others would be interested in what he was doing that was bypassing this.

 

Best,

Tom

Posted
I would suggest looking into the logs on the Smoothwall and filtering them via the IP address of the client machine at the time. This should indicate whether you're getting the expected authentication, and what filtering polices were in effect.
  • 8 years later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...