Mr_J Posted October 20, 2018 Posted October 20, 2018 We are trying to get the reading eggs app (https://readingeggs.co.uk/apps/) to work on iPads - through our Smoothwall S4 device. We have been on to Smoothwall support and they've been great, but all we have found is that in order to get it to work we need to do one of the following: - Disable Google Safe Search - Disable HTTPS Inspection Neither of which are an option really! We have the list of URL's and IP's that reading eggs need unblocking (which is pretty extensive btw - i'll put it at the end of this post!) - butting these in the exclusions doesn't seem to resolve it, so i'm looking to the wonderful people on here! There are a lot of Smoothwall appliances out there, and they even sponsor this group! SURELY there is one user out there with reading eggs on a Smoothwall site.... please ... ANYONE! URLS unblocked: readingeggspress.com.au stats.pusher.com student.mathseeds.com 1. allow access to *.readingeggs.com 2. allow access to .readingeggs.com.au 3. allow access to .readingeggs.co.za 4. allow access to .readingeggs.co.uk 5. allow access to *.readingeggspress.com 6. allow access to *.readingeggsassets.com 7. 180.240.184.0/24 8. 200.201.194.16/28 9. 200.201.213.48/28 10. 192.16.0.0/18 11. 5.104.64.0/21 12. 46.22.64.0/20 13. 68.232.32.0/20 14. 72.21.80.0/20 15. 93.184.208.0/20 16. 110.232.176.0/22 17. 117.18.232.0/21 18. 108.161.240.0/20 19. 117.103.183.0/24 20. 198.7.16.0/20 21. 192.30.0.0/19 22. 192.16.10.0/24 23. 213.65.58.192/26
mrwoberts Posted October 20, 2018 Posted October 20, 2018 Hmmm, I'm just thinking that most of your list of exceptions are not URLs. How/where are you adding those exceptions? I agree, that list is very broad, and all over the world! Another thing to check is, have you specified anywhere (sorry I'm not a Smoothie user), not to allow direct IP address connections (or something similar)?
Mr_J Posted October 24, 2018 Author Posted October 24, 2018 Hi @mrwoberts Thank you for the reply. I've tried adding these IP's as a location in the exceptions and its still not having any of it. I've tried "anywhere" and also specified IP's. I don't really want to exclude the ipad's from HTTPS inspection completely - only when it's using this particular app. Very frustrating now as we are having the same thing with another app... "prodigy maths". J
brougham Posted October 31, 2018 Posted October 31, 2018 You really don't have to disable HTTPS inspection for everything on the iPads. Take that list, clean it up and bung it in a custom category. Go to 'Guardian » HTTPS inspection » Manage policies' find a policy that has the action of 'Do not inspect' above the inspection rule for your iPads,
Mr_J Posted December 5, 2018 Author Posted December 5, 2018 So, we're still trying to get this working! Smoothwall have been amazing and spent so much time trying to get this working - huge thanks to them. But I think we have all hit a brick wall with this! It's not so much the reading eggs IPs that are the issue ... its GOOGLE! See bellow reply from smoothwall: ====================================================================================== Hi, Thank you both for your patience on this issue. As discussed on the phone this afternoon, we have narrowed the issue down to Google Safesearch. We can see from the real-time web filter logs that with Safesearch enabled, the application fails with a Certificate error, which is generally caused by certificate pinning. This is designed to ensure that they send encrypted data over insecure networks. The down side of this is that they use an internally hard coded certificate location, and the MITM HTTPS certificate breaks the apps certificate "chain of trust" which then stops the applications from working correctly or at all. This is unfortunately in the apps design to stop MITM attacks, so there's no work around apart from not inspecting the traffic from the application. Usually it is fine to not inspect traffic from a specific application, as nothing else uses the URL's / domains, but unfortunately in this case, the application is build on Googles API's which trigger Safesearch.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now