Jump to content

Recommended Posts

Posted (edited)

Hi all,

In our school, we have a SmoothWall firewall, and our Desktop computers (on a local Active Directory managed by RM) are connected by an Ethernet cable on a specific VLAN. That VLAN, on the SmoothWall, was configured to use Kerberos as the authentication method, which works great for Web Filtering. However, more and more of our computers are portable devices, managed by Intune. Even some of the local Active Directory machines have been switched to Intune. For these computers, we have been using Wi-Fi, as it uses RADIUS for authentication, but quite a few of them, ideally, should be connected with an Ethernet cable, as they are shared machines. This makes it inconvenient for students having to "Forget" the Wi-Fi network, and having to re-log into the Wi-Fi every time they want to log on to a machine for a lesson.

 

With all this said, I was wondering if there's a way for the Web Filtering to work with Azure Active Directory sessions on Intune computers connected with an Ethernet cable. I have changed the Authentication settings to "Core Authentication", which allows content to be searched, and whatnot, however, even though I have added our Azure Active Directory to the SmoothWall, and mapped the groups, as per this article, I still cannot see users activity in the Web Filter. It's like it's not authenticating.

 

Many thanks,

Bruno.

Edited by brunoandrade98
Posted

Hi Bruno

 

I would recommend you take a look at our cloud filter extension - with managed devices and Azure, that will definitely be the best option when used in conjunction with the on-prem Smoothwall.

One more thing to do, if active directory accounts are still used/synced with Azure is to install our iDex agent on the domain controllers. This will look for successful audit entries for domain logins and send that to the Smoothwall - meaning Smoothwall should know who you are by the time you start browsing if you have logged on to a domain account. Talk to the account manager to setup an auth review and rework - iDex is simple to setup.

 

Core auth is not an active auth method - what it does is simply lookup the information in the user activity list found in services - authentication. If there is a user logged in on the IP address the proxy got the request from, the proxy will use that info. If there is no user logged in on that IP, the proxy will treat the request as unauthenticated. RADIUS, iDex, login scripts all work with core auth.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...