Jump to content

Recommended Posts

Posted
I had a Smoothwall migration to new hardware and some reconfiguration work moving to transparent proxy earlier this week, but on the transparent network (which is set to use core identification using idex on the domain controller's) the Smoothwall is not picking up any of the users details and just gives them access via our set default unauthenticated IP's, does anyone have any suggestions, I logged a support call but not heard anything back yet and the original engineer is unavailable
Posted (edited)

Hi,

 

We've just had Smoothwall installed last week so am really new but we had a similar issue but we had some users showing up as users rather than IPs.

 

Make sure the agent is installed on all DCs we only had it on one DC originally.

 

We also had a bit of a battle getting everything setup at the start and changed the IP address of the Smoothwall box but the agent was originally setup on the original incorrect IP.

 

They might be worth checking out?

 

Also it might be worth speaking with your account manager to try and speed up support.

Edited by mullet_man
Posted

Hi,

 

Thanks for the suggestions, idex is running on both DC's and I can see the directories and user count under diagnose.

 

I will call again this morning

Posted

Hiya,

I just went to IDex on our DCs recently and had to do a firewall rule to allow it to contact Smoothwall (Linky) after that we then had *some* users showing up as ip rather than usernames, Turns out if you have things in your exceptions lists it won't even bother to work out a username and just throw an IP at you. We removed all but the bare essentials on the Auth exceptions and lots of user names started to pop in.

Posted
I have checked the firewall settings under smoothwall access and the two IP's are configured to allow Idex traffic, I checked the authentication exceptions and for the purposes of testing removed them all, this made no difference, as soon as I put the smoothwall proxy in everything starts to work properly
Posted

Hi,

 

No problems I will take any suggestions but yes Transparent Proxy and Core Authentication is set up on Port 1

Posted
Often after a move to iDex, there's leftover items in the authentication exceptions in web proxy - authentication - exceptions. Exceptions there are meant for when various software cant respond to an active proxy auth request, like NTLM or Kerberos. With iDex, RADIUS on BYOD and/or login scripts, auth exceptions should no longer be needed. Anything going to a destination exempt from authentication would show up as unauthenticated.
Posted
Make sure Smoothwall is seeing the same IP address ranges as your AD as well - eg. if idex reports tom is logged in as 192.168.12.13 and then 192.168.10.12 hits the smoothie, there'll be no correlation.
Posted
Turns out that my DC's are not auditing account logins, policy is enabled and correct, so need to investigate this
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...