Jump to content

Recommended Posts

Posted

Hi all,

 

Just wondered how most people have filtering setup for Exa. We are currently due to switch to them as an ISP and just getting my head around how best to configure the filtering.

 

We do have a publicly accessible WiFi during holiday periods as we have a lot of external bookings with the college. As such I do not want them to be faced with certificate errors when they browse the internet.

 

I suppose my questions are:

 

Is it possible to exclude HTTPs decrypting on particular IP range (one that we will not expect the certificate to be installed on)?

If not, is my only option to turn off SSL decryption on the connection, and push all internal devices (what we want SSL filtering on) through the proxy?

 

Any advice or suggestions please fire away.

Posted

Hi,

 

We have an Exa connection and use their filtering.

 

You can indeed ask them to exclude a certain internal IP range from SSL filtering - we have this in place and it works. It's the only way we could find for devices without the certificate to be able to browse without error messages.

Posted
You can indeed ask them to exclude a certain internal IP range from SSL filtering - we have this in place and it works. It's the only way we could find for devices without the certificate to be able to browse without error messages.

 

We asked and with the new systems they put you on it either doesnt work or cant be done. We have guests coming all the time and have to faff around installing the SSL certificate on all their devices with various versions of Android and iOS which have to be done is slightly different ways, most guests just give up and put up with no Internet.

 

If you get it working on your new connection then please update this thread on how you did it. Thanks.

Posted
We asked and with the new systems they put you on it either doesnt work or cant be done. We have guests coming all the time and have to faff around installing the SSL certificate on all their devices with various versions of Android and iOS which have to be done is slightly different ways, most guests just give up and put up with no Internet.

 

If you get it working on your new connection then please update this thread on how you did it. Thanks.

 

It may be different with different connection set ups then - we are on leased-line fibre, with on-premises Stormshield firewall box. We also have the capability to sync with AD and select filtering profiles by AD group etc.

 

Maybe if you are on the cloud-hosted filtering option it is not possible then.

Posted
It may be different with different connection set ups then - we are on leased-line fibre, with on-premises Stormshield firewall box. We also have the capability to sync with AD and select filtering profiles by AD group etc.

 

Maybe if you are on the cloud-hosted filtering option it is not possible then.

 

We have a 200Mbps leased line with a Fortinet firewall onsite. It's the Filtering System that requires the SSL, not the firewall.

Posted

Just got Exa installed.

 

You have multiple external IPs, each can be filtered differently, so have an SSID for guests that goes out via a different IP

 

Our last system had timed based filtering, so I allowed games at break/lunch. Surfprotect doesn't do that yet so I added a proxy on Fortigate to output via a different IP (have to use cli), and set a proxy.pac file to use a different proxy at break time (DST, grr, bugs), that ip then uses transparent filtering which has games enabled.

 

The amount of urls that aren't categorised yet seems rather high though

  • 2 weeks later...
Posted

So finally got around to doing the different external IPs for different SSIDs

 

1. Different dhcp server for guest ssid, different internal ip range, different gateway

2. On fortigate internal interface add new gateway ip as a secondary ip

3. On fortigate WAN interface add another exa ip of the 16.

4. Create an IP Pool containing just that IP

5. Add an ipv4 policy for packets from that range to use the ip pool.

6. On surfprotect add a new policy using that ip, and then phone them to disable https transparent inspection

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...