Jump to content

Recommended Posts

Posted

We are using a Smoothwall proxy appliance S8 for web filtering.

 

We have three domain controllers, they were all replicating fine. Yesterday one of the domain controllers x.x.x.42 decided to stop responding. It needed three reboots to get it working again, lovely windows updates. It's all back to normal now, replicating no problems.

 

x.x.x.42 does not hold any FSMO roles. At some point, I do want to remove this server.

 

The problem is, while I was rebooting this domain controller, users could not browse any websites but were presented with a proxy authentication box.

 

My question is, why did Smoothwall not use the other two domain controllers to authenticate users for web filtering?

 

Cheers

Posted

As said above, worth checking which DCs are used for DNS on the appliance.

 

Also, maybe if you have a quiet time during half term to test this again by taking the DC offline, (and without making too many assumptions that this wasn't tried at the time) would a reboot or logging back on to clients authenticate against one of the other DCs?

Was everyone affected?

 

Would Core auth/IDex work for your implementation? The main caveat being that user switching can cause misidentification as it uses login events on the DCs.

  • Thanks 1
Posted

Plus one for iDex. Active proxy auth is a problem as so many apps and third party software use http and https these days and none of them have any support for proxy authentication.

 

The Smoothwall is connected to your AD - it should not matter if one DC disappears for a while, the AD connection should still work, everything else being equal, so definitely something not quite right. Take a look at using iDex as well or instead of - it's worth it.

  • Thanks 1
Posted

I have noticed that in Smoothwall my DNS servers are listed in “DNS forwarders”

(Network | DNS)

 

Should they really be in the “conditional DNS forwarders” section?

 

Think I might make and play with iDex next week during half term

Posted

Re DNS - the setup is normally that ISP and other external DNS are used as forwarders and your local AD DNS are used as conditional forwarders for your domain. However, as long as your internal DNS servers are capable of external lookups, your setup will work fine as well.

 

My preferred setup for DNS when using Smoothwall as firewall is to user external DNS as forwarders, internal AD DNS as conditional forwarders for the AD domain and then on the AD servers, use Smoothwall as their forwarder. This makes Smoothwall the common DNS cache for the network and optimises external lookups.

  • Thanks 1
Posted

I've moved my DNS servers to conditional forwarders

 

Just run the "Functionality tests" for authentication

 

All come back green apart from the below which has a status with an orange exclamation mark

 

Machine account dNSHostName matches system hostname smoothwall

 

Should this be of any concern?

  • 2 weeks later...
Posted

Finally had a chance to sort this.

 

Moved my internal DNS servers to conditional forwarding in smoothwall.

Removed the troublesome domain controller from network.

 

Cheers all for the pointers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...