Jump to content

Recommended Posts

Posted
Just to confirm that we've been having the same issues as timbo343 since the return to school in September - no idea why, no config changes etc. After the same support from Smoothwall, the LogonExclusions = nt authority\anonymous logon has sorted the issue. I will continue testing over the coming days to see if we have any further issues with misidentification.

 

I have tried this but the NT AUTHORITY\ANONYMOUS LOGON is still showing up in services > User activity on smoothwall, and builds up after a few days again with users report being banned as the smoothwall is seeing them as NT AUTHORITY\ANONYMOUS LOGON again.

 

This too has started since September for us.

 

Did you put anything else in LogonExclusions? Did you put NT AUTHORITY\ANONYMOUS LOGON in quotes as it has spaces?

Posted (edited)
I have tried this but the NT AUTHORITY\ANONYMOUS LOGON is still showing up in services > User activity on smoothwall, and builds up after a few days again with users report being banned as the smoothwall is seeing them as NT AUTHORITY\ANONYMOUS LOGON again.

 

This too has started since September for us.

 

Did you put anything else in LogonExclusions? Did you put NT AUTHORITY\ANONYMOUS LOGON in quotes as it has spaces?

 

Here is what is on all our DCs.

 

Make sure you restart the service too on each of the servers and then run the SendADDataNow from C:\Program Files\Smoothwall\IDexAgent.

 

LogonExceptions.PNG

Edited by timbo343
  • Thanks 1
Posted
Here is what is on all our DCs.

 

Make sure you restart the service too on each of the servers and then run the SendADDataNow from C:\Program Files\Smoothwall\IDexAgent.

 

[ATTACH=CONFIG]67385[/ATTACH]

 

Thanks @timbo343

Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked!

  • Thanks 1
Posted
Thanks @timbo343

Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked!

 

Maybe point their tech to Smoothwall's documentation ;)

 

https://kb.smoothwall.com/hc/en-us/articles/360007256160-Smoothwall-Filter-Firewall-Installing-IDex-Agent-on-Your-Domain-Controller

 

Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IDexAgent\Parameters
  • 4 months later...
Posted
Thanks @timbo343

Smoothwall support told me to put the logonexclusions in the folder above, not in Parameters! Looks like this may have worked!

 

I'm amused, I have just been told the exact same thing by support and found this thread because it didn't seem to be working (oddly now it is after being moved and confirmed in their tech doc!)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...