CyBeRkId2002 Posted September 27, 2018 Posted September 27, 2018 Hi all, Just wondered how most people have filtering setup for Exa. We are currently due to switch to them as an ISP and just getting my head around how best to configure the filtering. We do have a publicly accessible WiFi during holiday periods as we have a lot of external bookings with the college. As such I do not want them to be faced with certificate errors when they browse the internet. I suppose my questions are: Is it possible to exclude HTTPs decrypting on particular IP range (one that we will not expect the certificate to be installed on)? If not, is my only option to turn off SSL decryption on the connection, and push all internal devices (what we want SSL filtering on) through the proxy? Any advice or suggestions please fire away.
crc-ict Posted September 28, 2018 Posted September 28, 2018 Hi, We have an Exa connection and use their filtering. You can indeed ask them to exclude a certain internal IP range from SSL filtering - we have this in place and it works. It's the only way we could find for devices without the certificate to be able to browse without error messages.
Fazza Posted September 28, 2018 Posted September 28, 2018 You can indeed ask them to exclude a certain internal IP range from SSL filtering - we have this in place and it works. It's the only way we could find for devices without the certificate to be able to browse without error messages. We asked and with the new systems they put you on it either doesnt work or cant be done. We have guests coming all the time and have to faff around installing the SSL certificate on all their devices with various versions of Android and iOS which have to be done is slightly different ways, most guests just give up and put up with no Internet. If you get it working on your new connection then please update this thread on how you did it. Thanks.
crc-ict Posted September 28, 2018 Posted September 28, 2018 We asked and with the new systems they put you on it either doesnt work or cant be done. We have guests coming all the time and have to faff around installing the SSL certificate on all their devices with various versions of Android and iOS which have to be done is slightly different ways, most guests just give up and put up with no Internet. If you get it working on your new connection then please update this thread on how you did it. Thanks. It may be different with different connection set ups then - we are on leased-line fibre, with on-premises Stormshield firewall box. We also have the capability to sync with AD and select filtering profiles by AD group etc. Maybe if you are on the cloud-hosted filtering option it is not possible then.
Fazza Posted October 1, 2018 Posted October 1, 2018 It may be different with different connection set ups then - we are on leased-line fibre, with on-premises Stormshield firewall box. We also have the capability to sync with AD and select filtering profiles by AD group etc. Maybe if you are on the cloud-hosted filtering option it is not possible then. We have a 200Mbps leased line with a Fortinet firewall onsite. It's the Filtering System that requires the SSL, not the firewall.
mavhc Posted October 3, 2018 Posted October 3, 2018 Just got Exa installed. You have multiple external IPs, each can be filtered differently, so have an SSID for guests that goes out via a different IP Our last system had timed based filtering, so I allowed games at break/lunch. Surfprotect doesn't do that yet so I added a proxy on Fortigate to output via a different IP (have to use cli), and set a proxy.pac file to use a different proxy at break time (DST, grr, bugs), that ip then uses transparent filtering which has games enabled. The amount of urls that aren't categorised yet seems rather high though
mavhc Posted October 17, 2018 Posted October 17, 2018 So finally got around to doing the different external IPs for different SSIDs 1. Different dhcp server for guest ssid, different internal ip range, different gateway 2. On fortigate internal interface add new gateway ip as a secondary ip 3. On fortigate WAN interface add another exa ip of the 16. 4. Create an IP Pool containing just that IP 5. Add an ipv4 policy for packets from that range to use the ip pool. 6. On surfprotect add a new policy using that ip, and then phone them to disable https transparent inspection
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now