Jump to content

Recommended Posts

Posted

Hi all,

 

We are installing Smoothwall over the Easter Half term. I have a question regarding the authentication to the internet. At the moment we have got a client that sits on the laptop/desktop and that reports back to the web filter. Does Smoothwall have an equivalent of that or is it only done via a Proxy?

 

Thanks

Posted

No they don't have the equivalent client, but a number of other options are available to provide identity. The fall back is a log in option on a block page, and you can control the timeout.

 

You'd be best discussing the options in the design stage of your install.

Posted (edited)

We came from Lightspeed - that did have a client to pass identity info to the web filter. Functionally I suppose it's similar but there's more components to using IDex than a client that directly communicates with the web filter; it's a separate service installed on the DCs.

 

Our Smoothwall engineer advised that a logon script would be a better option for us. Hence my advice to discuss the options :)

Edited by limawhiskey
Posted

There is also the IDEX Client which sits on the individual PCs, as an alternative to the agent (which runs on the DCs) - the agent basically tells Smoothwall whenever the DC receives a successful logon request and tells it the username and IP/computer it came from.

 

The client does similar to what the agent did with Lightspeed v2, it tells Smoothwall when someone logs on/off/unlocks etc.

  • Thanks 1
Posted
Sounds useful. It actually might be worth revisiting for us. Rightly or wrongly, I got the impression from the engineer that they prefer to avoid IDex identity implementations if possible.
Posted
Sounds useful. It actually might be worth revisiting for us. Rightly or wrongly, I got the impression from the engineer that they prefer to avoid IDex identity implementations if possible.

Huh, weird. I got the impression IDex was something they made up because they didn't want it constantly authenticating everyone against an AD connector. Although that was just from reading the docs, we had no engineer for our install as I wanted to save the money and DIY.

Posted

For all "domain" computers - I would use Active Directory Authentication....I do use AD authentication. Can't see the merit of IDEX for these devices. Remember you will need a certificate on all the PCs (via GPO or whatever) otherwise smoothwall can't see https traffic.

 

For BYOD devices - I recommend using smoothwall as a radius and DHCP server for the wireless newtwork. This allows users to do a 802.11x logon to wireless and smoothwall knows who they are from that first moment of connection without pop up screens or whatever....In fact...Apps don't generally open a browser window which you would have to do otherwise.

 

For school wireless devices (not on domain) ....well a captive portal with a timeout set to something less than the length of a lesson is probably the best way to go.

 

You should understand all the options and pros and cons...becuase smoothwall installers don't necessarily understand your environment - so you need to think it out before hand.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...