ozydave Posted February 10, 2023 Posted February 10, 2023 We are using a Smoothwall proxy appliance S8 for web filtering. We have three domain controllers, they were all replicating fine. Yesterday one of the domain controllers x.x.x.42 decided to stop responding. It needed three reboots to get it working again, lovely windows updates. It's all back to normal now, replicating no problems. x.x.x.42 does not hold any FSMO roles. At some point, I do want to remove this server. The problem is, while I was rebooting this domain controller, users could not browse any websites but were presented with a proxy authentication box. My question is, why did Smoothwall not use the other two domain controllers to authenticate users for web filtering? Cheers
FN-GM Posted February 10, 2023 Posted February 10, 2023 Check you're not pointing to 1 domain controller for authentication. Also check the same for DNS. 1
ChrisC Posted February 10, 2023 Posted February 10, 2023 As said above, worth checking which DCs are used for DNS on the appliance. Also, maybe if you have a quiet time during half term to test this again by taking the DC offline, (and without making too many assumptions that this wasn't tried at the time) would a reboot or logging back on to clients authenticate against one of the other DCs? Was everyone affected? Would Core auth/IDex work for your implementation? The main caveat being that user switching can cause misidentification as it uses login events on the DCs. 1
timbo343 Posted February 10, 2023 Posted February 10, 2023 Negotiate Kerberos/NTLMI'd recommend using Core Auth with Idex or AD. Im sure someone at smoothwall will correct me if im wrong, i think you'll need to switch out Neg Kerberos/NTLM when you move over to Maiden. Have a look at this thread. https://www.edugeek.net/showthread.php?t=229387 Idex has been better for us whilst using Core Auth. We still have smoothwall linking into AD too. 2
ibpalle Posted February 10, 2023 Posted February 10, 2023 Plus one for iDex. Active proxy auth is a problem as so many apps and third party software use http and https these days and none of them have any support for proxy authentication. The Smoothwall is connected to your AD - it should not matter if one DC disappears for a while, the AD connection should still work, everything else being equal, so definitely something not quite right. Take a look at using iDex as well or instead of - it's worth it. 1
ozydave Posted February 10, 2023 Author Posted February 10, 2023 I have noticed that in Smoothwall my DNS servers are listed in “DNS forwarders” (Network | DNS) Should they really be in the “conditional DNS forwarders” section? Think I might make and play with iDex next week during half term
ibpalle Posted February 10, 2023 Posted February 10, 2023 Re DNS - the setup is normally that ISP and other external DNS are used as forwarders and your local AD DNS are used as conditional forwarders for your domain. However, as long as your internal DNS servers are capable of external lookups, your setup will work fine as well. My preferred setup for DNS when using Smoothwall as firewall is to user external DNS as forwarders, internal AD DNS as conditional forwarders for the AD domain and then on the AD servers, use Smoothwall as their forwarder. This makes Smoothwall the common DNS cache for the network and optimises external lookups. 1
ozydave Posted February 10, 2023 Author Posted February 10, 2023 I've moved my DNS servers to conditional forwarders Just run the "Functionality tests" for authentication All come back green apart from the below which has a status with an orange exclamation mark Machine account dNSHostName matches system hostname smoothwall Should this be of any concern?
ozydave Posted February 25, 2023 Author Posted February 25, 2023 Finally had a chance to sort this. Moved my internal DNS servers to conditional forwarding in smoothwall. Removed the troublesome domain controller from network. Cheers all for the pointers
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now