Jump to content

Recommended Posts

Posted

Hi,

 

currently our chromebooks are on their own vlan / wifi sid

 

In smoothwall we have a transparent authentication policy for that subnet

with no authentication (students for unauthenticated requests)

 

Its simple and works but has some limitations, e.g. when

looking at a report for bandwidth usage by user you only get the IP

 

The IP's are given out via smoothwall DHCP on a 1 hour lease so

the report is pretty useless for historic reports / identifying the real users.

 

As a quick fix is it possible for smoothwall to report on say Top MAC addresses

bandwidth usage ?

 

Also for chromebooks the hostname always shows as UNKNOWN

(ipads show their name). Is there a way to get chromebooks

to show their hostname? Then I could up the lease time to say 7 days

which would enable identifying users in last week ?

 

Of course the best solution would probably be to change the authentication ?!

 

How do you do it e.g. do smoothwall still recommend "connect for chromebooks" as

the best option?

Posted

Are they shared devices?

 

You could try the Authentication Method "Redirect users to SSL logon page (with backgroup tab)" this would show a logon page in the browser for them to enter their credentials. There are some setting for the SSL Logon Page under Services>SSL Login.

 

RADIUS might also work for you if they are not shared devices.

 

Not personaly used "connect for chromebooks"...

Posted
Best option for Chromebooks is our new cloud filter extension. It is part of your license so have a chat with your account manager and he'll set you up with a license and help for installing and configuring.
Posted (edited)

Hi, each pupil has their own chromebook, i.e they are not shared.

 

At start of pandemic (2 years ago!) we got the offsite filtering working with smoothwalls help

My memory is a little vague but looking in google admin I can see there is an OU with an app extension jbldkhfglmgeihlcaeliadhipokhocnm

And in the smoothwall Directories we have Google as well as our Active directory

I used to move chromebooks going home into this OU to get the offsite filtering.

 

Is this what you mean by the cloud filter ?

 

Like I said this was a couple of years ago, does anything need updating ?

 

As we have on premise smoothwall would using cloud filter on site have any performance implications ?

 

Also I thought when we used the offsite filtering you had to view logs on the client ?

e.g. see https://kb.smoothwall.com/hc/en-us/articles/360006892380

OR do these logs get written back to on-premise box as I want to report on sites visited /blocked / bandwidth etc.

 

I guess it is not possible to have hostname visible in smoothwall's DHCP (currently UNKNOWN for chromebooks)

or report by MAC address (smoothwall doesn't see layer 2?)

 

thanks

 

edit: I don't have direct access to a smoothwall account manager as box is managed by LEA so I have to go through them

first which can be quite a slow / painful process!

Edited by mrstrong
Posted

The cloud filter clients are configured so traffic from the client is not intercepted by the onn-prem Smoothwall - ie, no double filtering.

 

Smoothwall does see layer 2 but the web filter does not. Any device not on the same subnet as the Smoothwall wouldn't be visible re MAC address so it's not the right tool for the job when it coomes to Guardian.

 

Logs can be viewed immediately on the client and generally after about 5 mins, on the on-prem or the cloud interface.

  • Thanks 1
Posted

Hi just got round to do some testing and can see the chromebook IP listed in the secret knock page ui/admin/cloud_filter

 

Also on chromebook I can see "smoothwall extension" version 1.0.31467 updated may 4th so guess it auto updates?

 

In web filter logs username is mostly now showing the full gmail account rather than IP :) (still a few records with the IP though)

 

Also noticed the Policy column in web filter log is blank when the username is a gmail (but populated when username is an IP).

Is this expected ?

 

Are there any other things I need to consider e.g. like when using ipads with an MDM you have to update tokens / certificates

every so often, and any performance implications ?

 

thanks again

Posted

The policy column only shows content if a policy has been matched. For anything that has not been specifically blocked or allowed the policy column will be blank.

 

Have you setup a Google directory connection and mapped OUs or groups in services - authentication - directories?

Posted

yes added google directory and can see /pupils OU mapped to local Students group

 

I can see urls being correctly identified (category is correct) and allowed /denied

so it's working but Policy column is completely blank even for urls in a category that is in

a web filter policy. realtime filter on client correctly reports policy (matched rule is policy number)

 

just looking at https insepction looks like someone has turned it off! I'll switch it back on and re-test

seem to remeber you have to log out of web interface and give it half an hour to sync policy changes back up to cloud ?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...