Jump to content

Recommended Posts

Posted

Morning all

 

We've had the Idex Agent installed on our DCs for a while now handling proxy authentication for our Apple Mac clients. This stopped working relatively recently (possibly after Leeds 59 update but unsure). The DCs have the required Audit policies enabled and logon 4624 events are being logged in the Security Event Logs. Despite this our AD bound Macs still get filtered as "Unauthorised Clients" as the Smoothwall isn't detecting user logons. Core Auth is selected on our Transparent Auth policy, as it always has been.

 

Installed Idex Agents on DCs were (the now legacy) version 1 and I have upgraded them all to version 2 but the issue remains.

 

I've raised a ticket but am awaiting help from support.

 

Anyone else seen this problem and found a solution?

 

Thanks

Posted (edited)

Yes it is, but thanks for the suggestion :-)

 

Firewall logs show the Idex Agents are successfully talking to the Smoothwall so I can only assume that the agents themselves aren't detecting the logons.

Edited by gybe78
Posted (edited)
Any word on what the v2 idex agents benefits are? i notice it has some settings for cloud etc.. but cant find any documentation on the smoothwall kb Edited by DGardiner
Posted
Any word on what the v2 idex agents benefits are? i notice it has some settings for cloud print etc.. but cant find any documentation on the smoothwall kb

 

No idea - just saw it was available and tried it as I had exhausted all other ideas

Posted
No idea - just saw it was available and tried it as I had exhausted all other ideas

 

If you go into the realtime system report on the machine, check to see if youre seeing authentication errors in the authentication filter

Posted
If you go into the realtime system report on the machine, check to see if youre seeing authentication errors in the authentication filter

 

Thanks for the suggestion but System > Authentication logs all look good - no errors.

 

And under Settings > Authentication > Directories my IDex Directory shows a healthy status.

Posted
Also im assuming you have - created an idex directory in the directories

 

Yup - as I say we've had it working for a long time..... it's only recently stopped detecting logins.

Posted
What may be a shout is to deploy the idex client to the macs if the agent isnt working, but id assume if the login events are showing on the server it should work
Posted
The event viewer - windows - applications - will show entries from the iDex agent. It may show what's going on. You can try to clear iDex info in the services - authentication - settings as well. If you do that, run the program files\smoothwall\idexagent\sendaddatanow.exe on one DC with the installed iDex agent to update the iDex directory on the SMoothwall with the AD groups again.
Posted

Thanks for the suggestion. Have already cleared the IDex info and run sendaddatanow.exe on a DC which completed successfully.

 

The Application Event log on the DCs just show entries every few seconds saying "There were no new logons to send". It's as though the Agents aren't detecting the events in the Security Event Log.

Posted (edited)
What are the numbers shown in the diagnostics for the idex directory - hover over it in services - authentication - directories and the diag button should pop up. If you try a domain login on a normal PC/Laptop, any results? Edited by ibpalle
Posted
What are the numbers shown in the diagnostics for the idex directory - hover over it in services - authentication - directories and the diag button should pop up.

 

Please see screenshot below....

 

Screenshot 2022-07-05 132941.png

Posted (edited)
All entries listed under Services > Authentication > User Activity show "Negotiate" as the auth method - these are all Windows domain client logins. For Mac clients there are no entries at all. Edited by gybe78
Posted

If the kerberos login script is running on clients, those will overwrite the iDex logins. The script refreshes every 2 minutes.

 

Try looking at the reports - realtime - system and select authentication in the section drop down list. Do you see any iDex activity there?

 

Everything in the diag looks fine.

Posted

We don't use the kerberos login script (& never have).

 

There isn't anything iDex related showing in the Realtime > System > Authentication log. Should there be?

Posted

We had an issue recently where iDex stopped working totally every night after the login purge , reboot smoothwall and it all worked again. No one was being authenticated and getting the basic levels where applicable (Tho these were all domain joined machines)

 

In the end we had to disable the "Enable Daily login purge" and it stopped happening. Always had it on, always at 3am, then just stopped...

  • Thanks 2
Posted
We had an issue recently where iDex stopped working totally every night after the login purge , reboot smoothwall and it all worked again. No one was being authenticated and getting the basic levels where applicable (Tho these were all domain joined machines)

 

In the end we had to disable the "Enable Daily login purge" and it stopped happening. Always had it on, always at 3am, then just stopped...

 

Thanks @tdk1069 - I'll reboot tonight and see if anything changes.

Posted

As we have a failover Smoothie I bit the bullet and rebooted - and what do you know iDex is now working!

 

Thanks everyone for your input - @tdk1069 I'll be sure to check what happens after the 3am purge.

Posted
As we have a failover Smoothie I bit the bullet and rebooted - and what do you know iDex is now working!

 

Thanks everyone for your input - @tdk1069 I'll be sure to check what happens after the 3am purge.

 

If it's what happened at two of our schools reboot fixed it (we have failovers too! and one school is a child of the other) but only till the purge, We ended up just turning off the 3am purge at both those sites in the "Hidden Backen" (Still laugh at the name) @ /ui/admin/hbd

  • 7 months later...
Posted

Just got this working, the instructions are ok but over about 4 different pages quite convoluted.

 

I also tripped up adding the firewall rule as that wasn't clear either.

 

All fine once you get trough to 2nd level support though.

 

Is there any advantage to installing the idex client on devices as well as the agent on the domain controller?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...