Jump to content

Recommended Posts

Posted

Changed over to idex for our windows devices over the weekend after a few issues with the vb script we were using before.

 

Mostly seems to work but quite a few times the smoothwall is identifying the computer rather than the user, if that makes sense? If I go to our smoothwalladress/login to check it shows as domain\computername$ being signed in, which means it gets our default level of filtering so staff cannot access resources, and children wont be identified.

 

I'm assuming the setup is right as it does work some of the time. it doesn't seem to be computer specific as sometimes a re-boot and re-login will sort the issue.

Posted
This is usually because something makes a request as the computer first... eg AV or something similar. I am sure there's an "ignore computery looking things" switch somewhere... but my memory fails. @ibpalle?
Posted
This is usually because something makes a request as the computer first... eg AV or something similar. I am sure there's an "ignore computery looking things" switch somewhere... but my memory fails. @ibpalle?

 

There is this bit in the guide:

 

OPTIONAL: Ignoring Specific Account Logons

Any service accounts on the domain will be picked up by IDex when called and may cause authentication and group-mapping conflicts for users.

 

When using IDex agent 2.2.4 and above:

 

Open the registry editor on the Domain Controller running IDex Agent.

Navigate to:

HKLM\SYSTEM\CurrentControlSet\Services\IDexAgent\Parameters.

Create a new 'String' key called 'LogonExclusions'. In the 'Value data' as any users in the format domain\user in a comma separated list.

Restart the IDex agent service. This will need to be done on all IDex installs.

This parameter has to be re-added after an upgrade of the IDex agent, so make sure to save the list for later use.

 

But I'm not not sure I could use this to get it to ignore computer accounts?

Posted

Ah, so it's lots of different computer accounts, rather than a few service accounts?

 

Have you considered moving to agent based (cloud) filtering? Might be more straightforward than idex.

Posted
Are the hostname logins actually iDex logins? Normally hostnames are not reported by iDex logins. They can be seen for RADIUS accounting in some cases. Check the user activity list for the method of login.
Posted
Are the hostname logins actually iDex logins? Normally hostnames are not reported by iDex logins. They can be seen for RADIUS accounting in some cases. Check the user activity list for the method of login.

 

They are showing as method Transparent kerberos authentication

 

Checking the event viewer on the server it was having a lot of errors communicating with the smoothwall. A Reboot of the smoothwall and DCs overnight seems to have stopped it generating these errors so hopefully things will run more smoothly today. I am seeing lots of idex auth method on the smoothwall so far this morning.

Posted

If you are seeing kerberos it means a proxy is using kerberos via redirect as an auth method. Devices on power but with no users logged into them will be showing as hostnames.

 

If you have updated iDex to 2.3.5 from software.smoothwall.com I would suggest trying without Kerberos. Use core authentication and see if that holds up - should give you a much cleaner user activity list.

Posted

It is set as 1.1 to be core auth, and then 1.2 to be Kerberos (via redirect), 1.3 Redirect users to SSL...

 

It's been like this since it was installed, should i remove the 1.2 option now? I'd imagine now that idex seems to be working better then it should never get to needing that anyway?

Posted
It is set as 1.1 to be core auth, and then 1.2 to be Kerberos (via redirect), 1.3 Redirect users to SSL...

 

It's been like this since it was installed, should i remove the 1.2 option now? I'd imagine now that idex seems to be working better then it should never get to needing that anyway?

 

Correct. You can actually have just the redirect to SSL login - iDex users wont see it as Smoothwall already knows who they are. Others will be asked to login manually.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...