Jump to content

Recommended Posts

Posted

Has anyone using Surfprotect managed to apply a policy to an IP range successfully? One of our schools moved over last week, and I'm having a bit of trouble getting staff iPads to behave...

 

Basically - I've given them a reserved IP address (let's say 10.74.160.51 &.52), and created a filtering profile in surfprotect to apply an SLT filtering policy to that IP range. But... they just get the Default - external IP address policy. I've tried support and they keep telling me to push the IP address through AD..!?

 

There should be a setting that pushes internal IP address info from the AD to the Surf Protect Proxy, we have seen this with other schools, but your AD doesn't appear to be sending this information.

 

I'm stuck, any ideas?

Posted

That's odd... as you are a new customer you would be using the Quantum filtering then. With the original version I could enter an internal IP range in, but when we moved over the Quantum, from what I understand, the person that migrated us at Exa had to tie an the internal IP range we dedicated to a Surfprotect rule to an external address and then use that on the filtering. I wasn't required to do anything except install the AD sync software on the server (basically running a couple of PowerShell scripts).

 

This is our Internal device settings, as you can see, it's using an IP range outside of our 10. range LAN.

 

Surfprotect.png

 

Are you talking to Exa directly, or speaking to a 3rd party?

 

Tagging @exa_mark as the all knowing being of Exa setup on here. :)

  • Thanks 1
Posted
Ah yes of course - it is Quantum that we've moved to. Speaking directly to Exa, I guess I need them to sort the rule but first line just keep telling me to push the IP info from AD :rolleyes:. @exa_mark help!
  • Thanks 1
Posted
Do you use the Exa Helpdesk system? Very useful if like me you're hardly near a phone https://help.exa.net.uk and you can select the specific product or service you have an issue with which in theory should go to the right team. Also I find it easier to follow. :)
  • Thanks 1
Posted

Morning @Dom_

 

I was away from the office yesterday afternoon in meetings, so not quite as quick as normal to respond, but I understand the team have been in touch with you already before I saw this post.

 

Is everything okay now? If you need anything else you are welcome to ring me directly on 0345 1451234 or PM me.

 

Thank you @DJ-1701 for point @Dom_ in my direction

  • Thanks 1
Posted
Morning @Dom_

 

I was away from the office yesterday afternoon in meetings, so not quite as quick as normal to respond, but I understand the team have been in touch with you already before I saw this post.

 

Is everything okay now? If you need anything else you are welcome to ring me directly on 0345 1451234 or PM me.

 

Thank you @DJ-1701 for point @Dom_ in my direction

 

Thanks Mark - yes, someone else from support got in touch with me and we're working on a solution now.

  • Thanks 1
  • 2 years later...
Guest Guest
Posted
Did you ever manage to get this working? We're about to take delivery of iPads which I'd like to do the same with and I've been told by our reseller that this isn't possible without using the AD proxy
Posted
Did you ever manage to get this working? We're about to take delivery of iPads which I'd like to do the same with and I've been told by our reseller that this isn't possible without using the AD proxy

 

Well, I have it up and working, and information about how that happened is in the thread, I would have thought @Dom_ would have it working too. ;)

 

Since a couple of years back I have been given more information on this though, and basically from what I have been told Quantum filtering cannot read internal IP's unless you are using the AD proxy.

 

So what you need is either:

 

1) Use the AD proxy on the device and create rules based on your internal static IP for the device, and then create a profile in Surfprotect based on the internal IP... or if not possible...

2) Request the static internal IP address to be mapped to an external address, which then you can use to create a profile in Surfprotect based on the external address.

Posted
On my fortigate firewall I have a IPv4 policy: if source is ip range then use dynamic ip pool, which is a single external IP from the 16 given to me by Exa, and then on the Quantum filtering portal I set that external IP to be not filtered

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...