Jump to content

Recommended Posts

Posted

I've been trying to get a grasp on an install of Smoothwall I have inherited. They appeared to have one category that they used for Auth bypass and general URL exclusion. This seems like a bad idea to me as you can't tell who has visited the sites you have unblocked, whether they have HTTPS issues or not.

 

So I've seperated them out and come across an issue I have never encountered before, and I'm not sure why. If a site is in the Bypass Auth list, obviously, a user is unknown so it drops to the unauthenticated IP, which is generally locked down. So how do you let a staff user through to a Bypass Auth site? Or do you not and I never notcied before?

 

Use case: Facebook. Needs HTTPS bypass for the app to work, but we only want staff to access it. Same for Whats App.

Posted (edited)

Do you have a HTTPS inspection policy for Staff, Facebook App, Everywhere, Do not inspect

Do you have a HTTPS inspection policy for Pupils, Facebook App, Everywere, Decrypt and inspect - this would cause the app to stop working for pupils.

 

Social Media categories would need to be unblocked for staff web filter policies, and blocked for pupils, would need to check that no urls for social media platforms are included in the Authentication bypass/exceptions.

 

Smoothwall have a KB article on WhatsApp - https://kb.smoothwall.com/hc/en-us/articles/360002134304-Configuring-the-Smoothwall-Filter-and-Firewall-to-Allow-Access-to-WhatsApp#:~:text=If%20the%20WhatsApp%20application%20doesn%27t%20work%20through%20a,as%20well%20as%20a%20Guardian%20and%20HTTPS%20Policy.

 

Hope this is some help...

Edited by drewp
  • Thanks 1
Posted

Solved my own issue I think, must have been talkiing to the Duck.

 

For future reference, there was no HTTPS Inspection Bypass category, and the HTTPS Incompatible Sites category had been added to the bypass auth category group. So created HTTPS inspection exception category so we can be more specific, not use Auth Bypass for troublesome apps.

Posted
Do you have a HTTPS inspection policy for Staff, Facebook App, Everywhere, Do not inspect

Do you have a HTTPS inspection policy for Pupils, Facebook App, Everywere, Decrypt and inspect - this would cause the app to stop working for pupils.

 

Social Media categories would need to be unblocked for staff web filter policies, and blocked for pupils, would need to check that no urls for social media platforms are included in the Authentication bypass/exceptions.

 

Smoothwall have a KB article on WhatsApp - https://kb.smoothwall.com/hc/en-us/articles/360002134304-Configuring-the-Smoothwall-Filter-and-Firewall-to-Allow-Access-to-WhatsApp#:~:text=If%20the%20WhatsApp%20application%20doesn%27t%20work%20through%20a,as%20well%20as%20a%20Guardian%20and%20HTTPS%20Policy.

 

Hope this is some help...

 

Thanks drewp, yes this basically the issue but across a wider context.

Posted

The authentication exceptions category are only auth exceptions if they have actually been placed in the web proxy - authentication - exceptions section. Otherwise it's just a normal category. You can still have HTTPS bypass and a generic allow for facebook for staff users and a block for everyone else but obviously users need to be identified.

 

By the way, Facebook and other social networks work fine in the browser with https inspection - it's the apps that are having issues - a compromise, if you need to monitor the social network traffic is to use a browser for access, not the apps.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...