Jump to content

Recommended Posts

Posted

Strange one.....

 

Just unboxed a new M1 Mac and joined it to AD and our MDM. All policies picked up including proxy settings and Smoothwall's MITM certificate which is trusted.

 

A student can logon with their AD credentials and get correctly filtered on http requests but ALL https traffic appears to be unfiltered. Nothing gets blocked and https traffic doesn't even appear in the Guardian logs.

 

Mac OS 11.3

 

Any ideas @ibpalle?

Posted
Check the transparent proxy config on Smoothwall - is HTTPS filtering enabled? Most likely not - once enabled, also remember to check the authentication policy for the transparent proxy and set the behaviour to allow transparent incompatible and filter others by cert.
Posted (edited)
Check the transparent proxy config on Smoothwall - is HTTPS filtering enabled? Most likely not - once enabled, also remember to check the authentication policy for the transparent proxy and set the behaviour to allow transparent incompatible and filter others by cert.

 

Hi

 

Currently we're using non transparent proxy. Proxy information (http/https) is being set by the MDM and I can see that some traffic from some applications is hitting the smoothwall logs, but not safari web browsing.

 

Do you recommend I switch to transparent?

 

And if so, where do I set the behaviour to allow transparent incompatible and filter others by cert?

 

Thanks for your help

Edited by gybe78
Posted
Not all apps honour proxy settings so I always recommend a mix - proxy settings are good for apps and browsers generally as they tell the app that a proxy is in use but for all other traffic, the transparent will intercept that.
  • Thanks 1
Posted

Currently we're using NTLM/Kerberos negotiation auth method on the non-transparent connection which works fine with Mac OS 10.x. Wondering if it isn't working for Mac OS 11.x and whether a different method is required - although I'd expect default behaviour to block traffic not allow it. What do you recommend?

 

Gonna have to open a support case I think :-(

Posted
I'd definitely look into using the iDex agent on domain controllers to handle user identification and using Kerberos/ntlm as a backup method.
Posted

So, looks like it's definitely an authentication problem. If I reboot a Mac and immediately login as a student, I get proxy authentication popups ask me to authenticate. I can dismiss these and browse to any nasty site on https which should be blocked, but isn't.

 

If I log off the student and log back on as the same student, I don't get proxy authentication popups and https traffic is filtered correctly and the block page shows the correct policy and group membership. It's as though authentication isn't happening quickly enough and doesn't retry.

Posted

I have a case open with support. We've tried using the iDex client on the Macs for authentication which works fine until the device is joined to Mosyle MDM. After this Smoothwall sees the client as an Unauthenticated IP device.

 

Anyone else got Smoothwall playing nicely with AD integrated Macs running OS 11 while being managed by an MDM?

Posted
No it doesn’t. The MDM is pushing a proxy profile to push the localhost:8080 settings. Really odd.
  • 7 months later...
Posted
Did you ever get this resolved? We have a selection of Imacs that are suddenly showing up as unauthenticated IPs, when using Idex in Smoothwall. It was working up until a few weeks ago. Our Macs are managed by Filewave.
Posted
Did you ever get this resolved? We have a selection of Imacs that are suddenly showing up as unauthenticated IPs, when using Idex in Smoothwall. It was working up until a few weeks ago. Our Macs are managed by Filewave.

 

Is iDex still working for the non MAC devices?

Posted
Yes we've had no reported issues. It was ok on the Macs as well until a couple of weeks ago. We have checked the Idex agents on the DCs and they are running, with no errors.
Posted
If one of the MACs access a file server, does an iDex entry then show up for the user? Since the iDex entry only shows after a successful AD login I'd like to see if an iDex login is seen after using AD credentials to access a resource in the domain. Sometimes MACs and AD logins depend on what type of software is used for joining the domain.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...