Jump to content

Recommended Posts

Posted

Our smoothie is set to use Negotiate/Kerberos Authentication and generally seems to be working (I've not been at this school too long!) but I've noticed and issue when trying to allow a group of sites (i.e Remote access Teamviewer) for specific users

 

At the very top of our policy list is an allow list for those sites, with users specified in the domain\username format. At the bottom of our policy list is a default block list which blocks those sites for everyone else

 

However it blocks it for the allowed users, and when I check the logs the access to (for example) teamviewer.com are coming through as the IP Address in the user name and the code 200 and being picked up by the catch all rule at the end

 

Am I being thick here as I can't see what I've done wrong? When I check the Domain settings (using the Diagnose option) it all shows OK with green ticks all the way

Posted
Is that site in a "do not auth for" list - it's entirely possible that your predecessor decided that teamviewer hated being authenticated...

 

You nailed it! It was buried in one of the exception lists - I feel a bit dense for not finding it but admittedly I skimmed those lists too quickly initially

Posted
You nailed it! It was buried in one of the exception lists - I feel a bit dense for not finding it but admittedly I skimmed those lists too quickly initially

 

This is not a density issue ;)

Posted (edited)
For future reference Under guardians categories, there is a category tester that you can put any site in and it will return all the categories it found in both custom and built in. Not to be confused with policy tester. Edited by dapaulio

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...