Sheridan Posted August 8, 2024 Posted August 8, 2024 Our smoothie is set to use Negotiate/Kerberos Authentication and generally seems to be working (I've not been at this school too long!) but I've noticed and issue when trying to allow a group of sites (i.e Remote access Teamviewer) for specific users At the very top of our policy list is an allow list for those sites, with users specified in the domain\username format. At the bottom of our policy list is a default block list which blocks those sites for everyone else However it blocks it for the allowed users, and when I check the logs the access to (for example) teamviewer.com are coming through as the IP Address in the user name and the code 200 and being picked up by the catch all rule at the end Am I being thick here as I can't see what I've done wrong? When I check the Domain settings (using the Diagnose option) it all shows OK with green ticks all the way
tom_newton Posted August 8, 2024 Posted August 8, 2024 Is that site in a "do not auth for" list - it's entirely possible that your predecessor decided that teamviewer hated being authenticated... 2
Sheridan Posted August 8, 2024 Author Posted August 8, 2024 Is that site in a "do not auth for" list - it's entirely possible that your predecessor decided that teamviewer hated being authenticated... You nailed it! It was buried in one of the exception lists - I feel a bit dense for not finding it but admittedly I skimmed those lists too quickly initially
ibpalle Posted August 8, 2024 Posted August 8, 2024 You should consider using iDex and core auth to avoid having to use auth exceptions. They are very annoying
tom_newton Posted August 8, 2024 Posted August 8, 2024 You nailed it! It was buried in one of the exception lists - I feel a bit dense for not finding it but admittedly I skimmed those lists too quickly initially This is not a density issue
dapaulio Posted August 9, 2024 Posted August 9, 2024 (edited) For future reference Under guardians categories, there is a category tester that you can put any site in and it will return all the categories it found in both custom and built in. Not to be confused with policy tester. Edited August 9, 2024 by dapaulio
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now