5tu Posted July 16, 2021 Posted July 16, 2021 Strange one..... Just unboxed a new M1 Mac and joined it to AD and our MDM. All policies picked up including proxy settings and Smoothwall's MITM certificate which is trusted. A student can logon with their AD credentials and get correctly filtered on http requests but ALL https traffic appears to be unfiltered. Nothing gets blocked and https traffic doesn't even appear in the Guardian logs. Mac OS 11.3 Any ideas @ibpalle?
PaddyNewman Posted July 16, 2021 Posted July 16, 2021 Assuming your Smoothwall has a block on QUIC? If not, add that in there sharpish.
5tu Posted July 17, 2021 Author Posted July 17, 2021 Yep QUIC already blocked but thanks for the reply
ibpalle Posted July 19, 2021 Posted July 19, 2021 Check the transparent proxy config on Smoothwall - is HTTPS filtering enabled? Most likely not - once enabled, also remember to check the authentication policy for the transparent proxy and set the behaviour to allow transparent incompatible and filter others by cert.
5tu Posted July 19, 2021 Author Posted July 19, 2021 (edited) Check the transparent proxy config on Smoothwall - is HTTPS filtering enabled? Most likely not - once enabled, also remember to check the authentication policy for the transparent proxy and set the behaviour to allow transparent incompatible and filter others by cert. Hi Currently we're using non transparent proxy. Proxy information (http/https) is being set by the MDM and I can see that some traffic from some applications is hitting the smoothwall logs, but not safari web browsing. Do you recommend I switch to transparent? And if so, where do I set the behaviour to allow transparent incompatible and filter others by cert? Thanks for your help Edited July 19, 2021 by gybe78
ibpalle Posted July 19, 2021 Posted July 19, 2021 Not all apps honour proxy settings so I always recommend a mix - proxy settings are good for apps and browsers generally as they tell the app that a proxy is in use but for all other traffic, the transparent will intercept that. 1
5tu Posted July 19, 2021 Author Posted July 19, 2021 Currently we're using NTLM/Kerberos negotiation auth method on the non-transparent connection which works fine with Mac OS 10.x. Wondering if it isn't working for Mac OS 11.x and whether a different method is required - although I'd expect default behaviour to block traffic not allow it. What do you recommend? Gonna have to open a support case I think :-(
ibpalle Posted July 19, 2021 Posted July 19, 2021 I'd definitely look into using the iDex agent on domain controllers to handle user identification and using Kerberos/ntlm as a backup method.
5tu Posted July 19, 2021 Author Posted July 19, 2021 So, looks like it's definitely an authentication problem. If I reboot a Mac and immediately login as a student, I get proxy authentication popups ask me to authenticate. I can dismiss these and browse to any nasty site on https which should be blocked, but isn't. If I log off the student and log back on as the same student, I don't get proxy authentication popups and https traffic is filtered correctly and the block page shows the correct policy and group membership. It's as though authentication isn't happening quickly enough and doesn't retry.
5tu Posted July 22, 2021 Author Posted July 22, 2021 I have a case open with support. We've tried using the iDex client on the Macs for authentication which works fine until the device is joined to Mosyle MDM. After this Smoothwall sees the client as an Unauthenticated IP device. Anyone else got Smoothwall playing nicely with AD integrated Macs running OS 11 while being managed by an MDM?
ibpalle Posted July 22, 2021 Posted July 22, 2021 Does the MDM enforce proxy settings that are different from the ones the iDex client requires? (localhost 8080)
5tu Posted July 24, 2021 Author Posted July 24, 2021 No it doesn’t. The MDM is pushing a proxy profile to push the localhost:8080 settings. Really odd.
ibpalle Posted July 26, 2021 Posted July 26, 2021 Are localhost and internal subnets excluded from proxying?
emmah Posted March 16, 2022 Posted March 16, 2022 Did you ever get this resolved? We have a selection of Imacs that are suddenly showing up as unauthenticated IPs, when using Idex in Smoothwall. It was working up until a few weeks ago. Our Macs are managed by Filewave.
5tu Posted March 16, 2022 Author Posted March 16, 2022 Yes but only by implementing idex agents on our DCs.
ibpalle Posted March 17, 2022 Posted March 17, 2022 Did you ever get this resolved? We have a selection of Imacs that are suddenly showing up as unauthenticated IPs, when using Idex in Smoothwall. It was working up until a few weeks ago. Our Macs are managed by Filewave. Is iDex still working for the non MAC devices?
psydii Posted March 17, 2022 Posted March 17, 2022 Private Relay? https://support.apple.com/en-gb/HT212614
emmah Posted March 18, 2022 Posted March 18, 2022 Yes we've had no reported issues. It was ok on the Macs as well until a couple of weeks ago. We have checked the Idex agents on the DCs and they are running, with no errors.
ibpalle Posted March 18, 2022 Posted March 18, 2022 If one of the MACs access a file server, does an iDex entry then show up for the user? Since the iDex entry only shows after a successful AD login I'd like to see if an iDex login is seen after using AD credentials to access a resource in the domain. Sometimes MACs and AD logins depend on what type of software is used for joining the domain.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now