gerardsweeney Posted February 12, 2021 Posted February 12, 2021 Hello, all.. Our local authority has being using DirectAccess for the last few years, and it's got us out of a fairly massive hole over the last year what with "one thing and another" (points if you get the reference). DA works well enough for file access (shared folders, network home folders). However - when we have clients hitting the WWW via our ForcePoint proxy over DirectAccess, the results are terrible. Users see a variety of errors like "The server reset", "ERR_EMPTY_RESPONSE". The result for the users is pages not loading properly (CSS missing, images missing etc). If they hit F5 often enough, the page will load properly - but it's far from good. The dead obvious solution of letting them go out direct is a complete no-go security wise. While all of these WWW issues are going on, the client has no issues at all connecting and staying connected to the network - 0 dropped PINGs of authority based servers. It does the same with different releases of Windows 10. On IE, Chrome, Edge, Edge Chromium. While these issues are happening for DA clients, if I remote onto a WIRED desktop or an 8021x laptop INSIDE the school, WWW browsing is absolutely fine. Is any of this ringing any bells for people who have used DA? Thanks! Gerard PS - our Infra team are looking at implementing Always On VPN, but that's likely to be a long(!) way off.
free780 Posted February 12, 2021 Posted February 12, 2021 You need split level tunneling with some sort of client Web Filtering.
MartinRouterKing Posted February 12, 2021 Posted February 12, 2021 Have you done an add route on the DA server and added the proxy server IP
gerardsweeney Posted February 12, 2021 Author Posted February 12, 2021 You need split level tunneling with some sort of client Web Filtering. Thanks for getting back to me. Client web filtering? Do you mean have something installed on the laptops which do the web filtering? Not an option, I'm afraid.
gerardsweeney Posted February 12, 2021 Author Posted February 12, 2021 Have you done an add route on the DA server and added the proxy server IP Umm.. OK - I'm just a desktop guy. How would I know if this has been done? The proxy does work - but the performance isn't great when there's a few people connected to DA. So during the weekend, it's useable. Mon-Friday from about 10am, it's broken.
free780 Posted February 13, 2021 Posted February 13, 2021 Thanks for getting back to me. Client web filtering? Do you mean have something installed on the laptops which do the web filtering? Not an option, I'm afraid.So Sophos Web Control can do domain blocking depending in category. It won't do SSL Interception. If your going to reroute all the Internet traffic back to site you will hit issues due to how much reliance there is on the cloud.
RobD Posted February 13, 2021 Posted February 13, 2021 We had the same issue so split them out to use their own internet and installed a client proxy (Cisco umbrella) so they couldn't look at unsuitable websites.
gerardsweeney Posted February 15, 2021 Author Posted February 15, 2021 Erk... These client based filtering options sound expensive and problematic... EG - the laptops jump from home use to being used on our 8021x network in the schools. So we'd need a way of only enabling the client based filter when on DA. And a way of easily synching the filter rules between the main filter and the client based one.. Hmm... I'll feed this back to the Boss Thanks for the replies so far!
RobD Posted February 15, 2021 Posted February 15, 2021 Depending on which one you get they have a probe like direct access i.e. are you on the network? Yes, then disable proxy. Or just use the client proxy permanently (DNS filtering) i.e. get rid of the server based proxy.
stm-tech Posted February 22, 2021 Posted February 22, 2021 How are you making your filtering? I ask because we use web safety and all the settings are applied via wpad and dhcp. So, when in school, they go through we safety, but at home the only filtering is done with Sophos. We also have IMPERO that will sync back to our servers once connected. Thoughts?
gerardsweeney Posted February 22, 2021 Author Posted February 22, 2021 How are you making your filtering? I ask because we use web safety and all the settings are applied via wpad and dhcp. So, when in school, they go through we safety, but at home the only filtering is done with Sophos. We also have IMPERO that will sync back to our servers once connected. Thoughts? We use ForcePoint WebSense. Users have all WWW traffic routed through that. The only setting that needs applied is the IE proxy and various exceptions. No client side software. I'm not sure Forcepoint even have a client side software package that would be included with whatever we use? Unless anyone knows otherwise?
chazzy2501 Posted February 23, 2021 Posted February 23, 2021 you can set domains to proxy (or not) on the direct access server, go through the wizard again and add some exceptions. (it been ages sorry not specific) I can't even remember the terminology used. but you can state if DA is used for certain domains. I remember sorting out a lot of issues by distributing the WPAD proxy.pac via DHCP instead of DNS.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now