Martin48 Posted December 14, 2023 Posted December 14, 2023 Dear all, Wondering if anyone knows this one as smoothwall support is absolutely awful, ticket open over a week and just 1 person who escalated then radio silence. I have multiple smoothwall appliances which sync to their own cloud portals, unfortunately I have 1 azure tenant. The first box I setup seems to have stolen all the users from azure, so when I removed 1 schools teachers they just became default users instead of being picked up by the other smoothwall which is fair enough. When I check the azureAD directory in advanced it has user and group filter option but no help on what to put here I would assume this will be needed but no reply from their support. Regards Martin Sykes
ibpalle Posted December 14, 2023 Posted December 14, 2023 The group and UOs should stay the same - Smoothwall does not change anything in Azure so unsure what you mean when you say Smoothwall has stolen users. Each Smoothwall and cloud config combination should have their own group mappings - they all just connect to the same directory. Is there any replication going on between Smoothwalls?
Martin48 Posted December 14, 2023 Author Posted December 14, 2023 As in all the users from azure are being handled by the first smoothwall box, as its the same azure tenant for all 3 boxes their needs to be a way to filter the users so 1 box doesn't end up getting all the users. From what I see the edge smoothwall extension doesn't have anything to say which smoothwall box its for, so it must be comparing the email to known users?
ibpalle Posted December 14, 2023 Posted December 14, 2023 (edited) So the group mappings you make on the 'first' smoothwall box is being replicated to all the others but you still have separate cloud configs for all sites, as in a cloud serial and separate portal for each site? If group mappings are replicated, they need to be standardised so you use the same groups on all sites - one local Smoothwall group can be mapped to multiple directory OUs or groups so make all the student group mappings on the first smoothwall for all sites, same with the other groups. Edited December 14, 2023 by ibpalle
Martin48 Posted December 14, 2023 Author Posted December 14, 2023 I have seperate smoothwall boxes and cloud settings for each site, each site syncs to its own cloud. But I have only 1 azure tenant for all 3 sites. So when I try to push the edge extension which doesn't ask which site its for, it is treating my user as a default user now I have removed the group mapping and I am trying to map that group from the other site, as I would prefer each team to manage their own sites staff.
ibpalle Posted December 14, 2023 Posted December 14, 2023 On each smoothwall box, you make the group mappings in the services - authentication - directories. In the portal, you make those mappings in the admin - smoothwall groups section. Each site, even though looking at the same directory, should be able to make their own group mappings in the directory.
Martin48 Posted December 14, 2023 Author Posted December 14, 2023 Thank you, I have done this, trouble is when their is no mapping on the first site i setup the user ends up in "default users" likely as that site is seeing the user as exists but isn't in a mapped group, the mappings on the other sites are there-for ineffective.
ibpalle Posted December 14, 2023 Posted December 14, 2023 The mappings should be separate for each system if the setup is as you describe. Mappings on one will not affect anything on the others. If there are no mappings then users end up as default users, which is the default behaviour when the filter knows your username but not your group membership so that's expected. However you then say this makes the other site mappings ineffective ... 1: unless there is replication going on settings are separate. 2: For some reason the cloud filter extension has been installed on the other sites using the cloud filter serial from the first site
Martin48 Posted December 18, 2023 Author Posted December 18, 2023 Thank you, I found the script what sets the serial numbers, our installer configured it at 1 site then it was forgotten about, I did ask on my support ticket how do I set serials but unfortunately your support still hasn't replied to anything since 8th December. 1
ibpalle Posted December 18, 2023 Posted December 18, 2023 Thanks for the feedback - support has had a backlog quite a bit bigger than previous years - again! We are expanding there - again! Just as a reminder, the kb.smoothwall.com site has a whole section on the cloud filter with the most recent install and diagnostics instructions.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now