Jump to content

Recommended Posts

Posted

I've set up a byod wifi which hits our smoothwall on a specific vlan - this has authentication set to 'No authentication' and 'Students for unauthenticated request'. The wifi splash page points to the 'getcert' page of the smoothwall

 

In principle this seems to work, but in some cases the splash page doesn't appear, or the user simply clicks away from it and then they can still access some blocked sites - for example I connected a Mac, authenticated with the wifi as a student and didn't install the certificate and I could still access instagram as a student

 

What I don't understand is that a) the smoothwall logs show the access going through as a Student account as '200 Success OK' - but in red for some reason and b) we have https inspection enforced on this subnet using a location so its should deliver an invalid certificate instead of letting access through?

 

We don't have any rules that would overrule this (especially not for students and social media) so I can't see how the filter is recognising the client as a student, the site as social media and still allowing it through?

 

Its in testing stages at the moment but this is a definite blocker in proceeding

Posted (edited)

100% would allow to only TCP80/443 via the filter and DNS via a service that scrubs ECH, not Google DNS, not quad9, but ideally your own internal one that you control. Easiest way out is a relaxed firewall and whatever DNS. 

 

For all other ports, please see your nearest 4G mast. 

Edited by PaddyNewman
  • Like 1
Posted

Hmm, applied remove QUIC header to all traffic now and its still the same - no certificate installed but access still being allowed (albeit missing some page elements)

 

Posted
2 minutes ago, PaddyNewman said:

Why not just hard block UDP 80 and UDP 443? Open to the destinations you need rather than the world (I would assume people block those ports by default anyway?)

We don't have these open as far as I can see, our smoothwall goes out through our firewall which only allows ip traffic - and the smoothwall is only using port 80/443 (and a couple of other random ports such as 2053 for Sage etc)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...