TechMonkey Posted October 4, 2023 Posted October 4, 2023 I've been trying to get a grasp on an install of Smoothwall I have inherited. They appeared to have one category that they used for Auth bypass and general URL exclusion. This seems like a bad idea to me as you can't tell who has visited the sites you have unblocked, whether they have HTTPS issues or not. So I've seperated them out and come across an issue I have never encountered before, and I'm not sure why. If a site is in the Bypass Auth list, obviously, a user is unknown so it drops to the unauthenticated IP, which is generally locked down. So how do you let a staff user through to a Bypass Auth site? Or do you not and I never notcied before? Use case: Facebook. Needs HTTPS bypass for the app to work, but we only want staff to access it. Same for Whats App.
drewp Posted October 4, 2023 Posted October 4, 2023 (edited) Do you have a HTTPS inspection policy for Staff, Facebook App, Everywhere, Do not inspect Do you have a HTTPS inspection policy for Pupils, Facebook App, Everywere, Decrypt and inspect - this would cause the app to stop working for pupils. Social Media categories would need to be unblocked for staff web filter policies, and blocked for pupils, would need to check that no urls for social media platforms are included in the Authentication bypass/exceptions. Smoothwall have a KB article on WhatsApp - https://kb.smoothwall.com/hc/en-us/articles/360002134304-Configuring-the-Smoothwall-Filter-and-Firewall-to-Allow-Access-to-WhatsApp#:~:text=If%20the%20WhatsApp%20application%20doesn%27t%20work%20through%20a,as%20well%20as%20a%20Guardian%20and%20HTTPS%20Policy. Hope this is some help... Edited October 4, 2023 by drewp 1
TechMonkey Posted October 4, 2023 Author Posted October 4, 2023 Solved my own issue I think, must have been talkiing to the Duck. For future reference, there was no HTTPS Inspection Bypass category, and the HTTPS Incompatible Sites category had been added to the bypass auth category group. So created HTTPS inspection exception category so we can be more specific, not use Auth Bypass for troublesome apps.
TechMonkey Posted October 4, 2023 Author Posted October 4, 2023 Do you have a HTTPS inspection policy for Staff, Facebook App, Everywhere, Do not inspect Do you have a HTTPS inspection policy for Pupils, Facebook App, Everywere, Decrypt and inspect - this would cause the app to stop working for pupils. Social Media categories would need to be unblocked for staff web filter policies, and blocked for pupils, would need to check that no urls for social media platforms are included in the Authentication bypass/exceptions. Smoothwall have a KB article on WhatsApp - https://kb.smoothwall.com/hc/en-us/articles/360002134304-Configuring-the-Smoothwall-Filter-and-Firewall-to-Allow-Access-to-WhatsApp#:~:text=If%20the%20WhatsApp%20application%20doesn%27t%20work%20through%20a,as%20well%20as%20a%20Guardian%20and%20HTTPS%20Policy. Hope this is some help... Thanks drewp, yes this basically the issue but across a wider context.
ibpalle Posted October 4, 2023 Posted October 4, 2023 The authentication exceptions category are only auth exceptions if they have actually been placed in the web proxy - authentication - exceptions section. Otherwise it's just a normal category. You can still have HTTPS bypass and a generic allow for facebook for staff users and a block for everyone else but obviously users need to be identified. By the way, Facebook and other social networks work fine in the browser with https inspection - it's the apps that are having issues - a compromise, if you need to monitor the social network traffic is to use a browser for access, not the apps. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now