compsue Posted September 20, 2022 Posted September 20, 2022 Hi, we have moved over to Fortinet for our filtering and certificates need installing to have access to the Internet. This has been done via a group policy for PC'S and laptops and is working fine. The problem is our head wants anyone who uses a device in school eg. Mobile phones or personal laptops to only do do when connected to our WiFi so we can keep a check on searches etc. Our technicians have managed to sort out how to install the certificate on an iPhone but not an Android device. Can anyone help? Plus, what happens when Ofsted come in and want to connect to the WiFi? They would not be able to get access to the Internet without the certificate. We have been told to set up another WiFi logon with some static ip addresses but have been unable to sort as of yet. Hope this makes sense and that someone can help? Apparently, no other school have said there is an issue apart from ours! Thanks
Aprice Posted September 20, 2022 Posted September 20, 2022 For a web filter to be any use now it needs to be able to inspect HTTPS traffic, any devices that are going to have traffic inspected need to have this certificate installed on them so they trust the web filter. Here's a guide for installing certificates on Android devices: https://support.securly.com/hc/en-us/articles/212869927-How-do-I-install-Securly-SSL-certificate-on-Android-device- Substitute their certificate for yours One option is to setup a separate WiFi network with a different address range and then tell the Fortinet not to apply HTTPS inspection to that range. This would allow users without the certificate installed to connect to the internet, however the filtering for these devices would effectively be non existent. This is our standard practice, we leave it up to the school whether they use this WiFi network or not. 1
DrBeaker Posted September 20, 2022 Posted September 20, 2022 We had similar with an old system Even installing the certificates on Android didn't fully work. But having severally limited resources never got to look at it further.
free780 Posted September 21, 2022 Posted September 21, 2022 My impression is that Google don’t like the MITM certificate. You probably spend a lot of time putting domains in an exception list due to MITM breaking apps in Android and iOS. Even without MiTM the fortinet can check domains and block known bad domains. The filtering needs to move to browser extensions really. Not possible on Android and iOS though.
Roberto Posted September 21, 2022 Posted September 21, 2022 My impression is that Google don’t like the MITM certificate. You probably spend a lot of time putting domains in an exception list due to MITM breaking apps in Android and iOS. Even without MiTM the fortinet can check domains and block known bad domains. The filtering needs to move to browser extensions really. Not possible on Android and iOS though. Lots of the big sites use certificate pinning or suchlike to prevent MITM attacks. Which is what traditional SSL inspection is doing, albeit we don't call it a MITM attack because we're doing it with good intentions. This problem is only going to get worse imo, I think you'll need a product that installs an agent on EUC devices in the future if you want to continue to monitor their traffic...
RLR Posted September 21, 2022 Posted September 21, 2022 We have a guide for each device: Windows, Chrome, IOS and Android. Android is always a pain as it depends on the version they are running. We have a separate wifi SSID for external people that come in that we regularly change the password to.
compsue Posted September 21, 2022 Author Posted September 21, 2022 What are you using for WiFi? Cambium I believe
mavhc Posted September 22, 2022 Posted September 22, 2022 You can set Fortinet to bypass filtering for certain groups, so question is how do you identify the groups, they're on a different SSID, so could do different IP range, or VLAN for example
free780 Posted September 22, 2022 Posted September 22, 2022 You can use FSSO (Fortinet Single Sign On). Auth can come from radius or even SAML. Different subnets/VLANS would be easier.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now