blu4 Posted February 9, 2018 Posted February 9, 2018 Hi all, We are installing Smoothwall over the Easter Half term. I have a question regarding the authentication to the internet. At the moment we have got a client that sits on the laptop/desktop and that reports back to the web filter. Does Smoothwall have an equivalent of that or is it only done via a Proxy? Thanks
limawhiskey Posted February 9, 2018 Posted February 9, 2018 No they don't have the equivalent client, but a number of other options are available to provide identity. The fall back is a log in option on a block page, and you can control the timeout. You'd be best discussing the options in the design stage of your install.
foofighterjim Posted February 9, 2018 Posted February 9, 2018 Yes they do, their IDex agent: https://help.smoothwall.net/Latest/Content/idex/about.htm
limawhiskey Posted February 9, 2018 Posted February 9, 2018 (edited) We came from Lightspeed - that did have a client to pass identity info to the web filter. Functionally I suppose it's similar but there's more components to using IDex than a client that directly communicates with the web filter; it's a separate service installed on the DCs. Our Smoothwall engineer advised that a logon script would be a better option for us. Hence my advice to discuss the options Edited February 9, 2018 by limawhiskey
Katy Posted February 9, 2018 Posted February 9, 2018 There is also the IDEX Client which sits on the individual PCs, as an alternative to the agent (which runs on the DCs) - the agent basically tells Smoothwall whenever the DC receives a successful logon request and tells it the username and IP/computer it came from. The client does similar to what the agent did with Lightspeed v2, it tells Smoothwall when someone logs on/off/unlocks etc. 1
limawhiskey Posted February 9, 2018 Posted February 9, 2018 Sounds useful. It actually might be worth revisiting for us. Rightly or wrongly, I got the impression from the engineer that they prefer to avoid IDex identity implementations if possible.
Katy Posted February 9, 2018 Posted February 9, 2018 Sounds useful. It actually might be worth revisiting for us. Rightly or wrongly, I got the impression from the engineer that they prefer to avoid IDex identity implementations if possible. Huh, weird. I got the impression IDex was something they made up because they didn't want it constantly authenticating everyone against an AD connector. Although that was just from reading the docs, we had no engineer for our install as I wanted to save the money and DIY.
AlanD Posted February 9, 2018 Posted February 9, 2018 For all "domain" computers - I would use Active Directory Authentication....I do use AD authentication. Can't see the merit of IDEX for these devices. Remember you will need a certificate on all the PCs (via GPO or whatever) otherwise smoothwall can't see https traffic. For BYOD devices - I recommend using smoothwall as a radius and DHCP server for the wireless newtwork. This allows users to do a 802.11x logon to wireless and smoothwall knows who they are from that first moment of connection without pop up screens or whatever....In fact...Apps don't generally open a browser window which you would have to do otherwise. For school wireless devices (not on domain) ....well a captive portal with a timeout set to something less than the length of a lesson is probably the best way to go. You should understand all the options and pros and cons...becuase smoothwall installers don't necessarily understand your environment - so you need to think it out before hand.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now