Jump to content

Recommended Posts

Posted

Morning all! :)

We've been using Smoothwall to authenticate for our BYOD from our UniFi network for a good year or so without any issues, however randomly a couple of days ago we started getting a lot of account lockouts and it was soon clear this was down to the users of the BYOD network. Removing the BYOD from our APs stopped this.

I'm now investigating and I can't seem to find a route cause and therefore no solution - Smoothwall has been rebooted and updated since in the hope that would help but alas no. Groups are correct and haven't changed, firewall logs are still showing traffic flowing and marked as allowed on ports 1812 and 1813 when requests are made. The only change I know to have happened since last weekend are windows server updates, however the servers only handle accounting, not authentication. 

I can't seem to find any useful logs on Smoothwall to check for BYOD authentication - can someone point me in the right direction please before I try support?

Posted

Look at the Services-Authentication-Directories page and you can run a diagnostic.
The logs can be found in Reports-Logs-System-Authentication service

Posted

Do you have an NPS server? Could a certificate have gone out of date?  There is a tickle in the back of my brain of an update that previously killed NPS somehow but I thought that was all dealt with.  I can't remember anymore though sorry

Posted

Certificates crossed my mind, but everything is done Smoothwall end. The auth logs only show successful group mappings and don't seem to hold any relevance to the auth failures :(

 

Posted

Issue found!

I had done some security housekeeping, one of the steps of which was ensuring NTLM v1 was disabled and v2 was enforced.

Smoothwall doesn't like this! FreeRadius apparently only works with v1 by default (nasty) but the support guy I've been dealing with says there's a way around that which he's going to look into with me later :)

 

  • Like 1
Posted

Ahhhh... crikey, not seen this one in years. Smoothwall has a trick to workaround a bug in some browsers where it retries broken NTLM packets, which can cause that. I thought there was a toggle to turn it on and off, but I cant find it off hand.

You could always disable account lockouts for password retries for a bit. 

We really need to be ditching NTLM entirely though - it goes away soon!

Posted
Just now, tom_newton said:

Ahhhh... crikey, not seen this one in years. Smoothwall has a trick to workaround a bug in some browsers where it retries broken NTLM packets, which can cause that. I thought there was a toggle to turn it on and off, but I cant find it off hand.

You could always disable account lockouts for password retries for a bit. 

We really need to be ditching NTLM entirely though - it goes away soon!

Yeah, Alex from support mentioned that it would almost certainly be replaced in the next proper version of SW. He did find something but the text in that config file made it clear it wasn't immutable - a restart or update of Smoothie would put it right back to where it was, so just not worth the hassle. Happy for now though, but obviously that's one thing to look forward to :)

Let me know if you need a feature request or anything raising for it.

 

Posted
On 25/03/2025 at 12:27, tom_newton said:

Ahhhh... crikey, not seen this one in years. Smoothwall has a trick to workaround a bug in some browsers where it retries broken NTLM packets, which can cause that. I thought there was a toggle to turn it on and off, but I cant find it off hand.

You could always disable account lockouts for password retries for a bit. 

We really need to be ditching NTLM entirely though - it goes away soon!

It's in Web proxy - Web proxy - settings - advanced. Called 'Resume interrupted NTLM connections'

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...