tomo1095 Posted March 11, 2016 Posted March 11, 2016 Alright, so we've had a situation, which has made us go down the route of disabling the internet for one user. Proxy settings for smoothwall are pushed out via Group Policy and not changeable for students. I've put the user in question in a filter policy to block the 'everything' category. When I've tried to log in to the students account on the computer I couldn't access anything on the internet (I get a proxy connection failed error) and couldn't change the proxy settings. But I've been stood watching him access BBC bitesize and games on Chrome. Then when I tried again 5 seconds after I got the same error. I'm at a total loss as to how he's managed it, any help would be brilliant!
tomo1095 Posted March 11, 2016 Author Posted March 11, 2016 That was my first question when I got the phonecall, but no. Definitely his own, I saw it with my own eyes.
tomo1095 Posted March 11, 2016 Author Posted March 11, 2016 The interface we use for the proxy for students accounts uses NTLM authentication... I've never had trouble with Chrome authenticating in the past. How can I check it isn't being bypassed? I presume it must be authenticating and putting the students into the right group seen as the account I'm blocking everything for is the one I'm getting proxy errors on, as if Smoothwalls just refusing the connection? We have an authentications exceptions category, but that only contains the Office 365 domains and the policy is way further down the hierarchy than the Block everything for the specific student? The only other way I'm aware of to bypass authentication is by using a different proxy port which is set to just authenticate as staff, but it's only used on staff devices.
yorkie Posted March 11, 2016 Posted March 11, 2016 Are you able to check the log for the computer that was used? If so you will be able to see what user was used to access the BBC web site.
foofighterjim Posted March 11, 2016 Posted March 11, 2016 Is your block policy at the top of the list (or above anything else that may apply to the user) in guardian?
Guest obsidianpillar Posted March 11, 2016 Posted March 11, 2016 He may have the Smoothwall Admin credentials? Previously, some organisations I've seen have the same password throughout their network for authentication. In one instance a business stored their Domain Admin password in their MDT Deployment Settings and it was the same password for everything. I'd look at the background with the student, is he computer literate beyond his age group? Do you have any auditing software that would be able for trace this and thus you would be able to understand what he's doing? You could block Chrome using a Software Restriction Policy inside of a GPO and force him to use IE? That way the proxy settings would propagate. I'm not too literate with Smoothwall (more Sophos) but seeing the proxy settings inside of a GPO 127.0.0.1 should surely stop everything? That's what I do with certain users in our environment that require the internet disabled in all cases the default proxy settings for IE propagate to Chrome unless configured differently with the ADM files. Let me know if you find out the eventual cause. I, like others would be interested in what he was doing that was bypassing this. Best, Tom
nile_c Posted March 15, 2016 Posted March 15, 2016 I would suggest looking into the logs on the Smoothwall and filtering them via the IP address of the client machine at the time. This should indicate whether you're getting the expected authentication, and what filtering polices were in effect.
Jawloms Posted February 6, 2025 Posted February 6, 2025 @mikes - You realise this thread is nearly nine years old? 1
mikes Posted February 6, 2025 Posted February 6, 2025 @mikes - You realise this thread is nearly nine years old? No sorry I saw it at the top of the list because web-seeker had replied to it - my mistake! 1
Oaktech Posted February 6, 2025 Posted February 6, 2025 Redirect proxy in internet settings to 127.0.0.1? Lockdown proxy settings. 1
dapaulio Posted February 6, 2025 Posted February 6, 2025 Have you got the sites listed in authentication exception policy or category group? This practically bypass all rules.
dapaulio Posted February 6, 2025 Posted February 6, 2025 (edited) lol just realised how old this thread was. Webseeker fault for reviving the thread. Edited February 6, 2025 by dapaulio
CrootUK Posted February 6, 2025 Posted February 6, 2025 yes indeed it is...SADLY! I reckon its a student aswell😂 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now