Jump to content

Recommended Posts

Posted

In a school that I have recently taken over, I have discovered that the school uses a transparent/in-line EXA proxy and it is only one web-filter rule for all users, regardless of whether they are staff or students. This has caused me some great concern, given sites like youtube.com are specified in the allow category. I have asked for separate policies to be created, which they have done and as such they are no longer transparent and require proxy details to be entered. Normally, I'd achieve this via a GPO, but since this school is Intune only for user and device policies, I am unsure of the best way to achieve this.

 

My main concern is that Intune user policies can be very slow to apply when a user logs in and I don't really want to apply the settings to the the devices as a whole, as if a member of staff logs onto a student device, they would then be forced through the student filtering at a device level. AI seems to suggest that managing it as a scheduled task would be the most reliable, but I can imagine that being a pain to modify in the future (it is suggesting a script that runs on a login trigger that determines whether the user is a student or staff - if starts with two numbers, is a student and all others are staff - and then applies the defined proxy as specified in the script).

 

We are actually moving away from EXA in February to Sophos and thus this will only be a stop-gap fix. Therefore I'm thinking maybe device policies would just be easier for that short time.

Posted

A lot will depend on whether you have Quantum or Quantum+ versions of SurfProtect as there are different mechanisms involved for each.

To get profiles to work you need some sort of LDAP integration. Quantum works via AD only (so would be no good with an Intune on environment) but Quantum+ can use Entra or Google too.  There needs to be a periodic sync of user details from AD/Entra/Google to SurfProtect so the proxy server can do the lookup and assign the right policy. The profiles can be set up to look for group membership and/or specific users - so if all staff are in a staff LDAP group, add that to the staff profile etc. The proxy server address used is the same for all users so there is no worries about who logs in getting the wrong profile usually. Sometimes the lookup fails and those users will get the default transparent proxy profile (which should be at least as restrictive as the student profile). You can see what profile you are being assigned by checking https://status.surfprotect.co.uk/.

I would suggest reaching out to Exa support for guidance on setting this up and so they can explain and caveats that could catch you out - the documentation isn't always as up to date as the product.

  • Like 1
Posted

Thanks both for the information. I currently have no idea whether we are Quantum or Quantum+. This service is managed by Entrust and it appears that I have limited ability within the SurfProtect portal.

 

For transparent connections, https://status.surfprotect.co.uk/ shows:

Quote

 

Success! Your internet connection is protected by SurfProtect.

You are using the Q16 Transparent HTTPS service and we're matching you to the default profile in your location.

 

Here's a summary of all the identifying infomation we were able to gather about you and your connection:

Location name:Redacted

Profile name:

Profile type:

Profile matched on:

External IP Address:Redacted

Internal IP Addresses:

Current device name:

Authenticated User Name:

Authenticated Groups:

 

For proxied connections, it shows:

Quote

 

Success! Your internet connection is protected by SurfProtect.

You are using the Q17 Proxy Explicit service and we're matching you to the profile named Redacted based on your proxy port, Redacted.

 

Here's a summary of all the identifying infomation we were able to gather about you and your connection:

Location name:Redacted

Profile name:Redacted

Profile type:proxy port

Profile matched on:Redacted

External IP Address:Redacted

Internal IP Addresses:

Current device name:

Authenticated User Name:

Authenticated Groups:

 

 

Posted

The product type for us is shown on the home page of the SurfProtect panel, where is shows the setup instructions etc. On the right there is a panel with the ID and product details.

 

Looking at the status details they have set it up based on a proxy port rather than group membership (I wasn't aware that was an option as all our profiles were set up using groups before I arrived here). I believe that will mean setting up a different proxy server address for each type of user then, and Intune is too slow half the time as you said.

The way we do it is via groups which has a single proxy server address for everyone and SurfProtect deciding what profile to apply. Our way does require the user details being on the SurfProtect servers but once done it largely just works for us. Oddly the times it has a problem for us is when the users computer needs a reboot rather than an issue on SurfProtect itself, but even then they get the transparent proxy.

  • Like 1
Posted (edited)

Ah I see, we are using "SurfProtect Quantum", so not Quantum+. I have raised a ticket with Entrust to see if we can use Quantum+. If I can keep the transparent proxy but force authentication via EntraID, that seems like it would achieve exactly what I need.

Edited by CHiLL

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...