Sheridan Posted April 7, 2025 Posted April 7, 2025 I've set up a byod wifi which hits our smoothwall on a specific vlan - this has authentication set to 'No authentication' and 'Students for unauthenticated request'. The wifi splash page points to the 'getcert' page of the smoothwall In principle this seems to work, but in some cases the splash page doesn't appear, or the user simply clicks away from it and then they can still access some blocked sites - for example I connected a Mac, authenticated with the wifi as a student and didn't install the certificate and I could still access instagram as a student What I don't understand is that a) the smoothwall logs show the access going through as a Student account as '200 Success OK' - but in red for some reason and b) we have https inspection enforced on this subnet using a location so its should deliver an invalid certificate instead of letting access through? We don't have any rules that would overrule this (especially not for students and social media) so I can't see how the filter is recognising the client as a student, the site as social media and still allowing it through? Its in testing stages at the moment but this is a definite blocker in proceeding
Sheridan Posted April 7, 2025 Author Posted April 7, 2025 Ah no - not on this vlan coming in - and I was using chrome for testing so may well be it! Cheers!
PaddyNewman Posted April 7, 2025 Posted April 7, 2025 (edited) 100% would allow to only TCP80/443 via the filter and DNS via a service that scrubs ECH, not Google DNS, not quad9, but ideally your own internal one that you control. Easiest way out is a relaxed firewall and whatever DNS. For all other ports, please see your nearest 4G mast. Edited April 7, 2025 by PaddyNewman 1
tom_newton Posted April 8, 2025 Posted April 8, 2025 The smoothwall DNS proxy can scrub ECH for you if you need it 1
Sheridan Posted April 9, 2025 Author Posted April 9, 2025 Our smoothie is set to use its internal DNS server
Sheridan Posted April 10, 2025 Author Posted April 10, 2025 Hmm, applied remove QUIC header to all traffic now and its still the same - no certificate installed but access still being allowed (albeit missing some page elements)
TechMonkey Posted April 10, 2025 Posted April 10, 2025 What does the policy tester say if set to detailed diagnostics?
PaddyNewman Posted April 10, 2025 Posted April 10, 2025 Why not just hard block UDP 80 and UDP 443? Open to the destinations you need rather than the world (I would assume people block those ports by default anyway?)
Sheridan Posted April 10, 2025 Author Posted April 10, 2025 Basically shows a block as far as I can see, yet the client laptop I'm testing on can open facebook/instagram - but some content is missing
Sheridan Posted April 10, 2025 Author Posted April 10, 2025 2 minutes ago, PaddyNewman said: Why not just hard block UDP 80 and UDP 443? Open to the destinations you need rather than the world (I would assume people block those ports by default anyway?) We don't have these open as far as I can see, our smoothwall goes out through our firewall which only allows ip traffic - and the smoothwall is only using port 80/443 (and a couple of other random ports such as 2053 for Sage etc)
tom_newton Posted April 11, 2025 Posted April 11, 2025 ECH perhaps then - https://kb.smoothwall.com/hc/en-us/articles/16651254132252-Ensure-BYO-devices-with-Encrypted-Client-Hello-ECH-are-filtered
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now