Jump to content

Recommended Posts

Posted

Coming to this rather late in the day...partly because RM have just released a client package for this....I thought I'd give filestream a go.

 

We already have a tenancy, sync, etc, eetc..

 

So installed the client...and of course - it wouldn't connect.

 

...I'm guessing this is because google does not (unless you change the registry/GPO for Filestream) support MITM certificates for inspection

 

Tried a wild card URL in the "Do not Inspect" policy list....for all google like domains...and that didn't work...perhaps it doesn't like authentication either (nothing appearing in "real time report" of course to help...

 

What does filestream like/not like with smoothwall? Somebody must of have done this?

Posted
Tried a wild card URL in the "Do not Inspect" policy list....for all google like domains...and that didn't work...

googleapis.com seems to be the main URL that File Stream accesses when I checked using Fiddler. There are also a few others...

 

pki.goog
goo.gl
google.com
googleapis.com

 

I would try putting googleapis.com in your authentication exceptions policy.

Posted

No; not having any luck with this.

 

Put the above URLs in authentication exceptions...and in inspection whitelist/don't inspect....and it won't connect.

 

BUT it will connect...if I connect the PC directly to the router.......so it has to be smoothwall getting in the way.

 

Added the certificates from smoothwall into the Filestream package following google's help...which makes it accept certificate for inspection...and NO doesn't work.

 

Added the registry entries suggested by google so that it accepts any certificate...and no; it doesn't work.

 

Did a support call with smoothwall....who added a load more of Google's URLs...practically anything and everything with google in its name...and opened two firewall ports not even mentioned by google,,,,,and no; it still won't connect.

 

Can get a web based connection to work of course....but that's not much use if you want to use google's drive space directly.....

 

Can't help thinking this should be standard stuff that fschool firewalls should be capable of supporting....without 7000 network managers each trying to fix it individually....

Posted
To be honest we deployed this without any drama - we already had the recommended Google addresses whitelisted and set to not SSL intercept on the Smoothwall and I set the registry key to not care about the cert. It just worked.
Posted

Did you open ports 139 and 445?

 

 

..if you whitelisted "all" the addresses listed by google (which seems to be a complete list of everything they possibly do)...I assume you no longer get any reports of what is being searched for in google....for example....

 

 

But, its encouraging to know that it can be made to work...

 

So if you include your smoothwall certificate in the package...you no longer need to include "do not inspect" in the rules....only "do not authenticate"....but perhaps you have not tried to tighten it up further....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...