Tod Posted December 6, 2022 Posted December 6, 2022 Just to confirm that we've been having the same issues as timbo343 since the return to school in September - no idea why, no config changes etc. After the same support from Smoothwall, the LogonExclusions = nt authority\anonymous logon has sorted the issue. I will continue testing over the coming days to see if we have any further issues with misidentification. I have tried this but the NT AUTHORITY\ANONYMOUS LOGON is still showing up in services > User activity on smoothwall, and builds up after a few days again with users report being banned as the smoothwall is seeing them as NT AUTHORITY\ANONYMOUS LOGON again. This too has started since September for us. Did you put anything else in LogonExclusions? Did you put NT AUTHORITY\ANONYMOUS LOGON in quotes as it has spaces?
timbo343 Posted December 6, 2022 Author Posted December 6, 2022 (edited) I have tried this but the NT AUTHORITY\ANONYMOUS LOGON is still showing up in services > User activity on smoothwall, and builds up after a few days again with users report being banned as the smoothwall is seeing them as NT AUTHORITY\ANONYMOUS LOGON again. This too has started since September for us. Did you put anything else in LogonExclusions? Did you put NT AUTHORITY\ANONYMOUS LOGON in quotes as it has spaces? Here is what is on all our DCs. Make sure you restart the service too on each of the servers and then run the SendADDataNow from C:\Program Files\Smoothwall\IDexAgent. Edited December 6, 2022 by timbo343 1
Tod Posted December 6, 2022 Posted December 6, 2022 Here is what is on all our DCs. Make sure you restart the service too on each of the servers and then run the SendADDataNow from C:\Program Files\Smoothwall\IDexAgent. [ATTACH=CONFIG]67385[/ATTACH] Thanks @timbo343 Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked! 1
timbo343 Posted December 6, 2022 Author Posted December 6, 2022 Thanks @timbo343 Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked! Maybe point their tech to Smoothwall's documentation https://kb.smoothwall.com/hc/en-us/articles/360007256160-Smoothwall-Filter-Firewall-Installing-IDex-Agent-on-Your-Domain-Controller Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDexAgent\Parameters
ibpalle Posted December 6, 2022 Posted December 6, 2022 Maybe point their tech to Smoothwall's documentation https://kb.smoothwall.com/hc/en-us/articles/360007256160-Smoothwall-Filter-Firewall-Installing-IDex-Agent-on-Your-Domain-Controller I have updated this KB to include the LogonExclusion information. 1
tdk1069 Posted May 2, 2023 Posted May 2, 2023 Thanks @timbo343 Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked! I'm amused, I have just been told the exact same thing by support and found this thread because it didn't seem to be working (oddly now it is after being moved and confirmed in their tech doc!)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now