AlanD Posted July 25, 2018 Posted July 25, 2018 Coming to this rather late in the day...partly because RM have just released a client package for this....I thought I'd give filestream a go. We already have a tenancy, sync, etc, eetc.. So installed the client...and of course - it wouldn't connect. ...I'm guessing this is because google does not (unless you change the registry/GPO for Filestream) support MITM certificates for inspection Tried a wild card URL in the "Do not Inspect" policy list....for all google like domains...and that didn't work...perhaps it doesn't like authentication either (nothing appearing in "real time report" of course to help... What does filestream like/not like with smoothwall? Somebody must of have done this?
Arthur Posted July 25, 2018 Posted July 25, 2018 Tried a wild card URL in the "Do not Inspect" policy list....for all google like domains...and that didn't work... googleapis.com seems to be the main URL that File Stream accesses when I checked using Fiddler. There are also a few others... pki.goog goo.gl google.com googleapis.com I would try putting googleapis.com in your authentication exceptions policy.
AlanD Posted July 27, 2018 Author Posted July 27, 2018 No; not having any luck with this. Put the above URLs in authentication exceptions...and in inspection whitelist/don't inspect....and it won't connect. BUT it will connect...if I connect the PC directly to the router.......so it has to be smoothwall getting in the way. Added the certificates from smoothwall into the Filestream package following google's help...which makes it accept certificate for inspection...and NO doesn't work. Added the registry entries suggested by google so that it accepts any certificate...and no; it doesn't work. Did a support call with smoothwall....who added a load more of Google's URLs...practically anything and everything with google in its name...and opened two firewall ports not even mentioned by google,,,,,and no; it still won't connect. Can get a web based connection to work of course....but that's not much use if you want to use google's drive space directly..... Can't help thinking this should be standard stuff that fschool firewalls should be capable of supporting....without 7000 network managers each trying to fix it individually....
Primus Posted July 27, 2018 Posted July 27, 2018 To be honest we deployed this without any drama - we already had the recommended Google addresses whitelisted and set to not SSL intercept on the Smoothwall and I set the registry key to not care about the cert. It just worked.
AlanD Posted July 28, 2018 Author Posted July 28, 2018 Did you open ports 139 and 445? ..if you whitelisted "all" the addresses listed by google (which seems to be a complete list of everything they possibly do)...I assume you no longer get any reports of what is being searched for in google....for example.... But, its encouraging to know that it can be made to work... So if you include your smoothwall certificate in the package...you no longer need to include "do not inspect" in the rules....only "do not authenticate"....but perhaps you have not tried to tighten it up further....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now